VLDB 2026 Research / reviewers in the wild / expert
Luigi V. Mancini
dblp:55/6061 · also Luigi Vincenzo Mancini
· DBLP profile ↗
98ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0003-4859-2191ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 59 · 2 first-author · 12 since 2021Systems, architecture and hardware · 11 · 1 first-author · 1 since 2021Computer networks · 10 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 6 · 2 first-authorHuman-computer interaction and ubiquitous computing · 4Theory of computation · 4Artificial intelligence and machine learning · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | I can't recognize (yet): Delayed Rendering to Defeat Visual Phishing Detectors
Ying Yuan 0002, Cristiano Alex Rado, Giovanni Apruzzese, Mauro Conti, Luigi V. Mancini |
EuroS&P | 5 |
| 2026 | MAYA: Addressing Inconsistencies in Generative Password Guessing Through a Unified BenchmarkabstractRecent advances in generative models have led to their application in password guessing, with the aim of replicating the complexity, structure, and patterns of human-created passwords. Despite their potential, inconsistencies and inadequate evaluation methodologies in prior research have hindered meaningful comparisons and a comprehensive, unbiased understanding of their capabilities. This paper introduces MAYA, a unified, customizable, plug-and-play benchmarking framework designed to facilitate the systematic characterization and benchmarking of generative password-guessing models in the context of trawling attacks. Using MAYA, we conduct a comprehensive assessment of six state-of-the-art approaches, which we re-implemented and adapted to ensure standardization. Our evaluation spans eight real-world password datasets and covers an exhaustive set of advanced testing scenarios, totaling over 15,000 compute hours. Our findings indicate that these models effectively capture different aspects of human password distribution and exhibit strong generalization capabilities. However, their effectiveness varies significantly with long and complex passwords. Through our evaluation, sequential models consistently outperform other generative architectures and traditional password-guessing tools, demonstrating unique capabilities in generating accurate and complex guesses. Moreover, the diverse password distributions learned by the models enable a multi-model attack that outperforms the best individual model. By releasing MAYA, we aim to foster further research, providing the community with a new tool to consistently and reliably benchmark generative password-guessing models. Our framework is publicly available at https://github.com/williamcorrias/MAYA-Password-Benchmarking. William Corrias, Fabio De Gaspari, Dorjan Hitaj, Luigi V. Mancini |
SP | 4 |
| 2025 | Minerva: A File-Based Ransomware DetectorabstractRansomware attacks have caused billions of dollars in damages in recent years, and are expected to cause billions more in the future. Consequently, significant effort has been devoted to ransomware detection and mitigation. Behavioral-based ransomware detection approaches have garnered considerable attention recently. These behavioral detectors typically rely on process-based behavioral profiles to identify malicious behaviors. However, with an increasing body of literature highlighting the vulnerability of such approaches to evasion attacks, a comprehensive solution to the ransomware problem remains elusive. This paper presents Minerva, a novel robust approach to ransomware detection. Minerva is engineered to be robust by design against evasion attacks, with architectural and feature selection choices informed by their resilience to adversarial manipulation. We conduct a comprehensive analysis of Minerva across a diverse spectrum of ransomware types, encompassing unseen ransomware as well as variants designed specifically to evade Minerva. Our evaluation showcases the ability of Minerva to accurately identify ransomware, generalize to unseen threats, and withstand evasion attacks. Furthermore, over of detected ransomware are identified within 0.52sec of activity, enabling the adoption of data loss prevention techniques with near-zero overhead. Dorjan Hitaj, Giulio Pagnotta, Fabio De Gaspari, Lorenzo De Carli, Luigi V. Mancini |
AsiaCCS | 5 |
| 2025 | Collaborative Countermeasure Against Network Traffic Analyses Based on Packet AggregationabstractNetwork traffic analysis attacks represent a significant threat to information security and user privacy. Leveraging machine learning, these attacks can infer sensitive information even when encryption and anonymization techniques are in place. This paper proposes TravelingTogether, a novel framework that leverages packet aggregation from multiple source hosts to defend users against network traffic analysis. TravelingTogether works at the network level, providing transparent and seamless protection to any hosts connected to the network. We evaluate our defense across different scenarios through a comprehensive set of experiments, demonstrating its effectiveness in thwarting website fingerprinting attacks as a representative use case, and its efficiency in terms of low time and bandwidth overhead. Riccardo Spolaor, Heyuan Shi, Fabio De Gaspari, Luigi V. Mancini, Dongxiao Yu, Xiuzhen Cheng |
ICC | 4 |
| 2025 | Do You Trust Your Model? Emerging Malware Threats in the Deep Learning EcosystemabstractTraining high-quality deep learning models is a challenging task due to computational and technical requirements. A growing number of individuals, institutions, and companies increasingly rely on pre-trained, third-party models made available in public repositories. These models are often used directly or integrated in product pipelines with no particular precautions, since they are effectively just data in tensor form and considered safe. In this paper, we raise awareness of a new machine learning supply chain threat targeting neural networks. We introduce MaleficNet 2.0, a novel technique to embed self-extracting, self-executing malware in neural networks. MaleficNet 2.0 uses spread-spectrum channel coding combined with error correction techniques to inject malicious payloads in the parameters of deep neural networks. MaleficNet 2.0 injection technique is stealthy, does not degrade the performance of the model, and is robust against removal techniques. We design our approach to work both in traditional and distributed learning settings such as Federated Learning, and demonstrate that it is effective even when a reduced number of bits is used for the model parameters. Finally, we implement a proof-of-concept self-extracting neural network malware using MaleficNet 2.0, demonstrating the practicality of the attack against a widely adopted machine learning framework. Our aim with this work is to raise awareness against these new, dangerous attacks both in the research community and industry, and we hope to encourage further research in mitigation techniques against such threats. Dorjan Hitaj, Giulio Pagnotta, Fabio De Gaspari, Sediola Ruko, Briland Hitaj, Luigi V. Mancini, Fernando Pérez-Cruz |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | TATTOOED: A Robust Deep Neural Network Watermarking Scheme based on Spread-Spectrum Channel CodingabstractDeep Neural Networks (DNNs) trained on proprietary company data offer a competitive edge for the owning entity. However, these models can be attractive to competitors (or malicious entities), who can copy or clone these proprietary DNN models to use them to their advantage. Since these attacks are hard to prevent, it becomes imperative to have mechanisms in place that enable an affected entity to verify the ownership of its DNN models with very high confidence. Watermarking of deep neural networks has gained significant traction in recent years, with numerous (watermarking) strategies being proposed as mechanisms that can help verify the ownership of a DNN in scenarios where these models are obtained without the owner’s permission. However, a growing body of work has demonstrated that existing watermarking mechanisms are highly susceptible to removal techniques, such as fine-tuning, parameter pruning, or shuffling.In this paper, we build upon extensive prior work on covert (military) communication and propose TATTOOED, a novel DNN watermarking technique that is robust to existing threats. We demonstrate that using TATTOOED as their watermarking mechanism, the DNN owner can successfully obtain the watermark and verify model ownership even in scenarios where 99% of model parameters are altered. Furthermore, we show that TATTOOED is easy to employ in training pipelines and has negligible impact on model performance. Giulio Pagnotta, Dorjan Hitaj, Briland Hitaj, Fernando Pérez-Cruz, Luigi V. Mancini |
ACSAC | 5 |
| 2024 | Have You Poisoned My Data? Defending Neural Networks Against Data Poisoning
Fabio De Gaspari, Dorjan Hitaj, Luigi V. Mancini |
ESORICS (1) | 3 |
| 2024 | FedComm: Federated Learning as a Medium for Covert CommunicationabstractProposed as a solution to mitigate the privacy implications related to the adoption of deep learning, Federated Learning (FL) enables large numbers of participants to successfully train deep neural networks without revealing theactualprivate training data. To date, a substantial amount of research has investigated the security and privacy properties of FL, resulting in a plethora of innovative attack and defense strategies. This paper thoroughly investigates the communication capabilities of an FL scheme. In particular, we show that a party involved in the FL learning process can use FL as a covert communication medium to send an arbitrary message. We introduce FedComm, a novel covert-communication technique that enables robust sharing and transfer of targeted payloads within the FL framework. Our extensive theoretical and empirical evaluations show that FedComm provides a stealthy communication channel, with minimal disruptions to the training process. Our experiments show that FedComm successfully delivers 100% of a payload in the order of kilobits before the FL procedure converges. Our evaluation also shows that FedComm is independent of the application domain and the neural network architecture used by the underlying FL scheme. Dorjan Hitaj, Giulio Pagnotta, Briland Hitaj, Fernando Pérez-Cruz, Luigi V. Mancini |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | DARD: Deceptive Approaches for Robust Defense Against IP TheftabstractWith the rise of smart working and recent global events, the risk of cyberattacks is increasing steadily. Sometimes adversaries focus on stealing valuable data, such as intellectual property (IP): they exfiltrate a large volume of IP documents from a target company. They then identify those of their interest by leveraging automated methods. This work proposes the DARD (Deceptive Approaches for Robust Defense against IP theft) system, a framework designed to deceive adversaries who rely on automatic approaches to classify exfiltrated documents. Starting from an original repository of documents, DARD automatically generates a new deceptive repository that misleads popular automatic approaches, resulting in clusters of documents that are significantly different from the actual ones. By utilizing this approach, DARD aims to hinder the accurate clustering and the identification of the topic of documents by adversaries relying on automated techniques. The paper presents four deceptive operations (Basic Shuffle, Shuffle increment, Shuffle reduction, and Change topic) that DARD leverages to create a deceptive repository. We evaluate the efficacy of our approach by considering three different types of adversaries, each possessing varying levels of knowledge and expertise. Through extensive experiments, we show that the DARD system can deceive both automatic topic modeling and document clustering techniques, including widely-used commercial tools such as Amazon Comprehend. Hence, our solution provides a robust defense mechanism against Intellectual Property (IP) theft. Alberto Maria Mongardini, Massimo La Morgia, Sushil Jajodia, Luigi V. Mancini, Alessandro Mei |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | DOLOS: A Novel Architecture for Moving Target DefenseabstractMoving Target Defense and Cyber Deception emerged in recent years as two key proactive cyber defense approaches, contrasting with the static nature of the traditional reactive cyber defense. The key insight behind these approaches is to impose an asymmetric disadvantage for the attacker by using deception and randomization techniques to create a dynamic attack surface. Moving Target Defense (MTD) typically relies on system randomization and diversification, while Cyber Deception is based on decoy nodes and fake systems to deceive attackers. However, current Moving Target Defense techniques are complex to manage and can introduce high overheads, while Cyber Deception nodes are easily recognized and avoided by adversaries. This paper presents DOLOS, a novel architecture that unifies Cyber Deception and Moving Target Defense approaches. DOLOS is motivated by the insight that deceptive techniques are much more powerful when integrated into production systems rather than deployed alongside them. DOLOS combines typical Moving Target Defense techniques, such as randomization, diversity, and redundancy, with cyber deception and seamlessly integrates them into production systems through multiple layers of isolation. We extensively evaluate DOLOS against a wide range of attackers, ranging from automated malware to professional penetration testers, and show that DOLOS is effective in slowing down attacks and protecting the integrity of production systems. We also provide valuable insights and considerations for the future development of MTD techniques based on our findings. Giulio Pagnotta, Fabio De Gaspari, Dorjan Hitaj, Mauro Andreolini, Michele Colajanni, Luigi V. Mancini |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2022 | PassFlow: Guessing Passwords with Generative FlowsabstractRecent advances in generative machine learning models rekindled research interest in the area of password guessing. Data-driven password guessing approaches based on GANs, language models, and deep latent variable models have shown impressive generalization performance and offer compelling properties for the task of password guessing.This paper proposes PassFlow, a flow-based generative model approach to password guessing. Flow-based models allow for precise log-likelihood computation and optimization, which enables exact latent variable inference. Additionally, flow-based models provide meaningful latent space representation, which enables operations such as exploration of specific subspaces of the latent space and interpolation. We demonstrate the applicability of generative flows to the context of password guessing, departing from previous applications of flow-networks which are mainly limited to the continuous space of image generation. We show that PassFlow is able to outperform prior state-of-the-art GAN-based approaches in the password guessing task while using a training set that is orders of magnitudes smaller than that of prior art. Furthermore, a qualitative analysis of the generated samples shows that PassFlow can accurately model the distribution of the original passwords, with even non-matched samples closely resembling human-like passwords. Giulio Pagnotta, Dorjan Hitaj, Fabio De Gaspari, Luigi V. Mancini |
DSN | 4 |
| 2022 | MaleficNet: Hiding Malware into Deep Neural Networks Using Spread-Spectrum Channel Coding
Dorjan Hitaj, Giulio Pagnotta, Briland Hitaj, Luigi V. Mancini, Fernando Pérez-Cruz |
ESORICS (3) | 4 |
| 2022 | Evading behavioral classifiers: a comprehensive analysis on evading ransomware detection techniquesabstractAbstract Recent progress in machine learning has led to promising results in behavioral malware detection. Behavioral modeling identifies malicious processes via features derived by their runtime behavior. Behavioral features hold great promise as they are intrinsically related to the functioning of each malware, and are therefore considered difficult to evade. Indeed, while a significant amount of results exists on evasion of static malware features, evasion of dynamic features has seen limited work. This paper examines the robustness of behavioral ransomware detectors to evasion and proposes multiple novel techniques to evade them. Ransomware behavior differs significantly from that of benign processes, making it an ideal best case for behavioral detectors, and a difficult candidate for evasion. We identify and propose a set of novel attacks that distribute the overall malware workload across a small set of independent, cooperating processes in order to avoid the generation of significant behavioral features. Our most effective attack decreases the accuracy of a state-of-the-art classifier from 98.6 to 0% using only 18 cooperating processes. Furthermore, we show our attacks to be effective against commercial ransomware detectors in a black-box setting. Finally, we evaluate a detector designed to identify our most effective attack, as well as discuss potential directions to mitigate our most advanced attack. Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
Neural Comput. Appl. | 5 |
| 2022 | Reliable detection of compressed and encrypted dataabstractAbstract Several cybersecurity domains, such as ransomware detection, forensics and data analysis, require methods to reliably identify encrypted data fragments. Typically, current approaches employ statistics derived from byte-level distribution, such as entropy estimation, to identify encrypted fragments. However, modern content types use compression techniques which alter data distribution pushing it closer to the uniform distribution. The result is that current approaches exhibit unreliable encryption detection performance when compressed data appear in the dataset. Furthermore, proposed approaches are typically evaluated over few data types and fragment sizes, making it hard to assess their practical applicability. This paper compares existing statistical tests on a large, standardized dataset and shows that current approaches consistently fail to distinguish encrypted and compressed data on both small and large fragment sizes. We address these shortcomings and design EnCoD, a learning-based classifier which can reliably distinguish compressed and encrypted data. We evaluate EnCoD on a dataset of 16 different file types and fragment sizes ranging from 512B to 8KB. Our results highlight that EnCoD outperforms current approaches by a wide margin, with accuracy ranging from $$\sim 82\%$$ ∼ 82 % for 512B fragments up to $$\sim 92\%$$ ∼ 92 % for 8KB data fragments. Moreover, EnCoD can pinpoint the exact format of a given data fragment, rather than performing only binary classification like previous approaches. Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
Neural Comput. Appl. | 5 |
| 2021 | MalPhase: Fine-Grained Malware Detection Using Network Flow DataabstractEconomic incentives encourage malware authors to constantly develop new, increasingly complex malware to steal sensitive data or blackmail individuals and companies into paying large ransoms. In 2017, the worldwide economic impact of cyberattacks is estimated to be between 445 and 600 billion USD, or 0.8% of global GDP. Traditionally, one of the approaches used to defend against malware is network traffic analysis, which relies on network data to detect the presence of potentially malicious software. However, to keep up with increasing network speeds and amount of traffic, network analysis is generally limited to work on aggregated network data, which is traditionally challenging and yields mixed results. In this paper we present MalPhase, a system that was designed to cope with the limitations of aggregated flows. MalPhase features a multi-phase pipeline for malware detection, type and family classification. The use of an extended set of network flow features and a simultaneous multi-tier architecture facilitates a performance improvement for deep learning models, making them able to detect malicious flows (>98% F1) and categorize them to a respective malware type (>93% F1) and family (>91% F1). Furthermore, the use of robust features and denoising autoencoders allows MalPhase to perform well on samples with varying amounts of benign traffic mixed in. Finally, MalPhase detects unseen malware samples with performance comparable to that of known samples, even when interlaced with benign flows to reflect realistic network environments. Michal Piskozub, Fabio De Gaspari, Frederick Barr-Smith, Luigi V. Mancini, Ivan Martinovic |
AsiaCCS | 4 |
| 2020 | The Naked Sun: Malicious Cooperation Between Benign-Looking Processes
Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
ACNS (2) | 5 |
| 2020 | EnCoD: Distinguishing Compressed and Encrypted File Fragments
Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini |
NSS | 5 |
| 2020 | SARA: Secure Asynchronous Remote Attestation for IoT SystemsabstractRemote attestation has emerged as a valuable security mechanism which aims to verify remotely whether or not a potentially untrusted device has been compromised. The protocols of Remote attestation are particularly important for securing Internet of Things (IoT) systems which, due to the large number of interconnected devices and limited security protections, are susceptible to a wide variety of cyber attacks. To guarantee the integrity of a software running on a single device, remote attestation is usually executed as an uninterrupted procedure: at the attestation time, a device stops the normal operation and executes the attestation of the entire device without interruption. The remote attestation protocols that aim to attest a large number of devices also follow the assumption on uninterrupted execution: when a device attests its network neighbours, each device verified in the neighborhood suspends its normal operation until the attestation protocol is completed. To avoid unnecessary suspension of the normal operation of the devices, this paper proposes a novel Secure Asynchronous Remote Attestation (SARA) protocol that releases the constraint of synchronous interaction among devices. In particular, SARA is an attestation protocol that exploits asynchronous communication capabilities among IoT devices in order to attest a distributed IoT service executed by them. SARA verifies both that each IoT device is not compromised (device trustworthiness), and that the exchanged communication data have not maliciously influence the communicating devices (legitimate operations). By tracing the execution order of each service invocation of an asynchronous distributed service, SARA allows each service to collect accurately historical data of its interactions, and transmits asynchronously such historical data to other interacting services. We have implemented and validated SARA through a realistic simulation on the Contiki emulator that demonstrates the functionality and efficiency of our protocol. The results confirm the suitability of SARA for low-end devices. Edlira Dushku, Md Masoom Rabbani, Mauro Conti, Luigi V. Mancini, Silvio Ranise |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | Know Your Enemy: Stealth Configuration-Information Gathering in SDN
Mauro Conti, Fabio De Gaspari, Luigi V. Mancini |
GPC | 3 |
| 2016 | Analyzing Android Encrypted Network Traffic to Identify User ActionsabstractMobile devices can be maliciously exploited to violate the privacy of people. In most attack scenarios, the adversary takes the local or remote control of the mobile device, by leveraging a vulnerability of the system, hence sending back the collected information to some remote web service. In this paper, we consider a different adversary, who does not interact actively with the mobile device, but he is able to eavesdrop the network traffic of the device from the network side (e.g., controlling a Wi-Fi access point). The fact that the network traffic is often encrypted makes the attack even more challenging. In this paper, we investigate to what extent such an external attacker can identify the specific actions that a user is performing on her mobile apps. We design a system that achieves this goal using advanced machine learning techniques. We built a complete implementation of this system, and we also run a thorough set of experiments, which show that our attack can achieve accuracy and precision higher than 95%, for most of the considered actions. We compared our solution with the three state-of-the-art algorithms, and confirming that our system outperforms all these direct competitors. Mauro Conti, Luigi V. Mancini, Riccardo Spolaor, Nino Vincenzo Verde |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Violating Consumer Anonymity: Geo-Locating Nodes in Named Data Networking
Alberto Compagno, Mauro Conti, Paolo Gasti, Luigi V. Mancini, Gene Tsudik |
ACNS | 4 |
| 2015 | Can't You Hear Me Knocking: Identification of User Actions on Android Apps via Traffic AnalysisabstractWhile smartphone usage become more and more pervasive, people start also asking to which extent such devices can be maliciously exploited as "tracking devices". The concern is not only related to an adversary taking physical or remote control of the device, but also to what a passive adversary without the above capabilities can observe from the device communications. Work in this latter direction aimed, for example, at inferring the apps a user has installed on his device, or identifying the presence of a specific user within a network. Mauro Conti, Luigi V. Mancini, Riccardo Spolaor, Nino Vincenzo Verde |
CODASPY | 2 |
| 2015 | No Place to Hide that Bytes Won't Reveal: Sniffing Location-Based Encrypted Traffic to Track a User's Position
Giuseppe Ateniese, Briland Hitaj, Luigi V. Mancini, Nino Vincenzo Verde, Antonio Villani |
NSS | 3 |
| 2015 | Obfuscation of Sensitive Data for Incremental Release of Network FlowsabstractLarge datasets of real network flows acquired from the Internet are an invaluable resource for the research community. Applications include network modeling and simulation, identification of security attacks, and validation of research results. Unfortunately, network flows carry extremely sensitive information, and this discourages the publication of those datasets. Indeed, existing techniques for network flow sanitization are vulnerable to different kinds of attacks, and solutions proposed for microdata anonymity cannot be directly applied to network traces. In our previous research, we proposed an obfuscation technique for network flows, providing formal confidentiality guarantees under realistic assumptions about the adversary's knowledge. In this paper, we identify the threats posed by the incremental release of network flows, we propose a novel defense algorithm, and we formally prove the achieved confidentiality guarantees. An extensive experimental evaluation of the algorithm for incremental obfuscation, carried out with billions of real Internet flows, shows that our obfuscation technique preserves the utility of flows for network traffic analysis. Daniele Riboni, Antonio Villani, Domenico Vitali, Claudio Bettini, Luigi V. Mancini |
IEEE/ACM Trans. Netw. | 5 |
| 2014 | No NAT'd User Left Behind: Fingerprinting Users behind NAT from NetFlow Records AloneabstractIt is generally recognized that the network traffic generated by an individual acts as his biometric signature. Several tools exploit this fact to fingerprint and monitor users. Often, though, these tools access the entire traffic, including IP addresses and payloads. In general, this is not feasible on the grounds that both performance and privacy would be negatively affected. In reality, most ISPs convert user traffic into Net Flow records for a concise representation that does not include the payload. More importantly, a single IP address belonging to a large and distributed network is usually masked using Network Address Translation techniques, thus a few IP addresses may be associated to thousands of individuals (NAT'd IPs). We devised a new fingerprinting framework that overcomes these hurdles. Our system is able to analyze a huge amount of network traffic represented as Net Flows, with the intent to track people. It does so by accurately inferring when users are connected to the network and which IP addresses they are using, even though thousands of users are hidden behind NAT. Our prototype implementation was deployed and tested within an existing large metropolitan WiFi network serving about 200,000 users, with an average load of more than 1,000 users simultaneously connected behind 2 NAT'd IP addresses only. Our solution turned out to be very effective, with an accuracy greater than 90%. We also devised new tools and refined existing ones that may be applied to other contexts related to Net Flow analysis. Nino Vincenzo Verde, Giuseppe Ateniese, Emanuele Gabrielli, Luigi V. Mancini, Angelo Spognardi |
ICDCS | 4 |
| 2013 | Uniqueness of the file systems genome: Supporting arguments and massive experimental measurementsabstractThis paper provides evidence of a distinguished feature of file systems, that we call File System Genome. Such a feature is originated by the locations where the file blocks are placed on the mass-storage device by the operating system during the installation procedure. It appears from our study that the File System Genome is a distinctive feature of each operating system installation. In particular, our extensive set of experiments shows that the installation of the same operating system on two identical hardware configurations generates two different File System Genomes. Further, the application of sound information theory tools, such as min entropy, show that the differences between two File System Genome are considerably relevant. The results provided in this paper constitute the scientific basis for a number of applications in various fields of information technology, such as devices' identification and security. Roberto Di Pietro, Luigi V. Mancini, Antonio Villani, Domenico Vitali |
CRiSIS | 2 |
| 2013 | Obsidian: A scalable and efficient framework for NetFlow obfuscationabstractThrough this software the authors aim to promote the sharing of network logs within the research community. The (k, j)obfuscation technique opens sundry interesting future directions. In fact, many networking and security tasks can be re-thought based on obfuscated datasets, for instance, quality of service (QoS), traffic classification, anomaly detection and more. Antonio Villani, Daniele Riboni, Domenico Vitali, Claudio Bettini, Luigi V. Mancini |
INFOCOM | 5 |
| 2012 | Relieve Internet Routing Security of Public Key InfrastructureabstractLack of security mechanisms expose the Border Gateway Protocol (BGP) to a wide range of threats that are constantly undermining security of the Internet. Most prominent attacks include prefix hijacking and announcement of false routes to maliciously attract or divert traffic. A number of cryptographic solutions to prevent both attacks have been proposed but have not been adopted due to involved operations and considerable overhead. Most of them rely on digital signatures to authorize Autonomous Systems to propagate route announcements. Surprisingly, the scientific community has devoted only little interest to the problem of revocation in BGP. In particular, BGP systems based on Public Key Infrastructure allow to revoke an Autonomous System by revoking its public key certificate. However, there seem to be no solution for selective revocation of AS-path announcements. This paper introduces reBGP, an enhanced version of BGP that leverages Identity Based Cryptography to secure BGP with minimal overhead. reBGP prevents prefix hijacking and false route announcement through Aggregate Identity Based Signatures and provides an effective revocation means to invalidate AS-path announcements. reBGP enjoys a constant overhead to verify authenticity of routes and does not require a Public Key Infrastructure. Extensive testing of our implementation, show that our proposal represents a practical solution to secure BGP. Luigi V. Mancini, Angelo Spognardi, Claudio Soriente, Antonio Villani, Domenico Vitali |
ICCCN | 1 |
| 2012 | Obfuscation of sensitive data in network flowsabstractIn the last decade, the release of network flows has gained significant popularity among researchers and networking communities. Indeed, network flows are a fundamental tool for modeling the network behavior, identifying security attacks, and validating research results. Unfortunately, due to the sensitive nature of network flows, security and privacy concerns discourage the publication of such datasets. On the one hand, existing techniques proposed to sanitize network flows do not provide any formal guarantees. On the other hand, microdata anonymization techniques are not directly applicable to network flows. In this paper, we propose a novel obfuscation technique for network flows that provides formal guarantees under realistic assumptions about the adversary's knowledge. Our work is supported by extensive experiments with a large set of real network flows collected at an important Italian Tier II Autonomous System, hosting sensitive government and corporate sites. Experimental results show that our obfuscation technique preserves the utility of network flows for network traffic analysis. Daniele Riboni, Antonio Villani, Domenico Vitali, Claudio Bettini, Luigi V. Mancini |
INFOCOM | 5 |
| 2012 | DDoS Detection with Information Theory Metrics and Netflows - A Real Case
Domenico Vitali, Antonio Villani, Angelo Spognardi, Roberto Battistoni, Luigi V. Mancini |
SECRYPT | 5 |
| 2011 | Secure topology maintenance and events collection in WSNsabstractAbstract Topology Maintenance Protocols (TMPs) are key for operating Wireless Sensor Networks (WSNs). Their adoption serves a few goals, such as, to save energy, to avoid collisions in communications and to have an adequate number of nodes monitoring the environment—by alternating duty cycles with sleep cycles on the sensor nodes. While effectiveness of TMPs protocols is widely addressed, security is an overlooked feature. Indeed, while different TMPs have been presented in the literature, few of them address the security issues. In particular, only recently a secure TMP protocol that does not require pair‐wise node confidentiality has been proposed: Sec‐TMP. The aim of Sec‐TMP is to enforce event delivery to the Base Station while providing a standard topology maintenance service to the WSN. In this paper, we provide a thorough assessment of our previous preliminary proposal of Sec‐TMP, with particular reference to its effectiveness and security. First, we investigate the energy consumption introduced by TMPs protocols. Second, we show that Sec‐TMP performs well without any assumption neither on the show‐up time of data‐collecting node, nor on their mobility model. In particular, we test Sec‐TMP against a realistic unpredictable data‐collecting mobility scenario, that also brings in new security issues. A thorough security analysis of the proposed solutions to these new issues is also provided. Finally, extensive simulations support the quality of Sec‐TMP as for effectiveness and security. Copyright © 2011 John Wiley & Sons, Ltd. Mauro Conti, Roberto Di Pietro, Andrea Gabrielli, Luigi V. Mancini |
Secur. Commun. Networks | 4 |
| 2011 | Distributed Detection of Clone Attacks in Wireless Sensor NetworksabstractWireless Sensor Networks (WSNs) are often deployed in hostile environments where an adversary can physically capture some of the nodes, first can reprogram, and then, can replicate them in a large number of clones, easily taking control over the network. A few distributed solutions to address this fundamental problem have been recently proposed. However, these solutions are not satisfactory. First, they are energy and memory demanding: A serious drawback for any protocol to be used in the WSN-resource-constrained environment. Further, they are vulnerable to the specific adversary models introduced in this paper. The contributions of this work are threefold. First, we analyze the desirable properties of a distributed mechanism for the detection of node replication attacks. Second, we show that the known solutions for this problem do not completely meet our requirements. Third, we propose a new self-healing, Randomized, Efficient, and Distributed (RED) protocol for the detection of node replication attacks, and we show that it satisfies the introduced requirements. Finally, extensive simulations show that our protocol is highly efficient in communication, memory, and computation; is much more effective than competing solutions in the literature; and is resistant to the new kind of attacks introduced in this paper, while other solutions are not. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2011 | Securing Topology Maintenance Protocols for Sensor NetworksabstractWe analyze the security vulnerabilities of PEAS, ASCENT, and CCP, three well-known topology maintenance protocols (TMPs) for sensor networks. These protocols aim to increase the lifetime of the sensor network by only maintaining a subset of nodes in an active or awake state. The design of these protocols assumes that the sensor nodes will be deployed in a trusted, nonadversarial environment, and does not take into account the impact of attacks launched by malicious insider or outsider nodes. We propose a metaprotocol (Meta-TMP) to represent the class of topology maintenance protocols. The Meta-TMP provides us with a better understanding of the characteristics and of how a specific TMP works, and it can be used to study the vulnerabilities of a specific TMP. We describe various types of malicious behavior and actions that can be carried out by an adversary to attack a wireless sensor network by exploiting the TMP being used in the network. We describe three attacks against these protocols that may be used to reduce the lifetime of the sensor network, or to degrade the functionality of the sensor application by reducing the network connectivity and the sensing coverage that can be achieved. Further, we describe countermeasures that can be taken to increase the robustness of the protocols and make them resilient to such attacks. Andrea Gabrielli, Luigi V. Mancini, Sanjeev Setia, Sushil Jajodia |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2010 | Hierarchies of keys in secure multicast communicationsabstractThis work considers key management for secure multicast in the Logical Key Hierarchy (LKH) model and proposes a methodology to establish the minimal key bit length that guarantees a specified degree of confidentiality for the multicast communications managed within this model. We also introduce the concepts of information lifetime and information dependence to formalize the intuition that keys should be longer, and thus stronger, when used to encrypt “important” information, that is information (including other keys) that need to be kept confidential for a longer period. Then, these concepts are used to build a formal theory that is applied to set the correct bit length of every key in the system in such a way to guarantee the prescribed degree of confidentiality of the multicast messages. Quite surprisingly, we formally show that not all the keys in the LKH hierarchy should have the same length; this observation, besides being of theoretical interest, also leads to substantial savings in terms of memory, computation, and bandwidth. The theory we develop to obtain these results can be useful in other contexts as well. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
J. Comput. Secur. | 2 |
| 2010 | eRIPP-FS: Enforcing privacy and security in RFIDabstractAbstract In RFID systems addressing security issues, many authentication techniques require the tag to keep some sort of synchronization with the reader. In particular, this is true in those proposals that leverage hash chains. When the reader and the tag get de‐synchronized, possibly by an attacker, this paves the way to several denial of service (DoS) attacks, as well as threatening privacy (e.g.,viathetiming attack). Even if de‐synchronization happens for non‐malicious causes, this event has a negative effect on performances (for instance, slowing down the authentication process). In this paper, we provide a solution to cope with the de‐synchronization between the tag and the reader when hash chains are employed. In particular, our solution relies on mutual reader‐tag authentication, achievedviahash traversal and Merkle tree techniques. We show that this techniques applied to an existing security protocol for RFID systems, such as RIPP‐FS, make timing attacks hard to succeed. Moreover, the proposed solutions can be transparently and independently adopted by similar security protocols as well to thwart timing attack and/or to provide reader‐tag mutual authentication. Finally, extensive simulations show that our proposal introduces a negligible overhead to recover de‐synchronization. Copyright © 2009 John Wiley & Sons, Ltd. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Angelo Spognardi |
Secur. Commun. Networks | 3 |
| 2009 | Sec-TMP: A Secure Topology Maintenance Protocol for Event Delivery Enforcement in WSN
Andrea Gabrielli, Mauro Conti, Roberto Di Pietro, Luigi V. Mancini |
SecureComm | 4 |
| 2009 | Playing hide-and-seek with a focused mobile adversary in unattended wireless sensor networks
Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
Ad Hoc Networks | 2 |
| 2009 | Privacy-preserving robust data aggregation in wireless sensor networksabstractAbstract In‐network data aggregationin wireless sensor networks (WSNs) is a technique aimed at reducing the communication overhead—sensed data are combined into partial results at intermediate nodes during message routing. However, in the above technique, some sensor nodes need to send their individual sensed values to an aggregator node, empowered with the capability to decrypt the received data to perform a partial aggregation. This scenario raises privacy concerns in applications like personal health care and the military surveillance. A few other solutions exist where the data are not disclosed to the aggregator (e.g., using privacy homomorphism (PH)), but these solutions are not robust to node or communication failure. The contributions of this paper are two‐fold: first, we design a private data aggregation protocol that does not leak individual sensed values during the data aggregation process. In particular, neither the base station (BS) nor the other nodes are able to compromise the privacy of an individual node's sensed value. Second, the proposed protocol is robust to data‐loss; if there is a node‐failure or communication failure, the protocol is still able to compute the aggregate and to report to the base station the number of nodes that participated in the aggregation. To the best of our knowledge, our scheme is the first one that efficiently addresses the above issues all at once. Copyright © 2009 John Wiley & Sons, Ltd. Mauro Conti, Lei Zhang 0004, Sankardas Roy, Roberto Di Pietro, Sushil Jajodia, Luigi V. Mancini |
Secur. Commun. Networks | 6 |
| 2009 | Data Security in Unattended Wireless Sensor NetworksabstractIn recent years, wireless sensor networks (WSNs) have been a very popular research topic, offering a treasure trove of systems, networking, hardware, security, and application-related problems. Much of prior research assumes that the WSN is supervised by a constantly present sink and sensors can quickly offload collected data. In this paper, we focus on unattended WSNs (UWSNs) characterized by intermittent sink presence and operation in hostile settings. Potentially lengthy intervals of sink absence offer greatly increased opportunities for attacks resulting in erasure, modification, or disclosure of sensor-collected data. This paper presents an in-depth investigation of security problems unique to UWSNs (including a new adversarial model) and proposes some simple and effective countermeasures for a certain class of attacks. Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
IEEE Trans. Computers | 2 |
| 2008 | Catch Me (If You Can): Data Survival in Unattended Sensor NetworksabstractUnattended sensor networks operating in hostile environments might collect data that represents a high-value target for the adversary. The unattended sensor's inability to off-load - in real time - sensitive data to a safe external entity makes it easy for the adversary to mount a focused attack aimed at eliminating certain target data. In order to facilitate survival of this data, sensors can collectively attempt to confuse the adversary by changing its location and content, i.e., by periodically moving the data around the network and encrypting it. In this paper, we focus on data survival in unattended sensor networks faced with an adversary intent on surgically destroying data which it considers to be of high value. After motivating the problem and considering several attack flavors, we propose several simple techniques and provide their detailed evaluation. Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
PerCom | 2 |
| 2008 | A Live Digital Forensic system for Windows networks
Roberto Battistoni, Alessandro Di Biagio, Roberto Di Pietro, Matteo Formica, Luigi V. Mancini |
SEC | 5 |
| 2008 | Scalable and efficient provable data possessionabstractStorage outsourcing is a rising trend which prompts a number of interesting security issues, many of which have been extensively investigated in the past. However, Provable Data Possession (PDP) is a topic that has only recently appeared in the research literature. The main issue is how to frequently, efficiently and securely verify that a storage server is faithfully storing its client's (potentially very large) outsourced data. The storage server is assumed to be untrusted in terms of both security and reliability. (In other words, it might maliciously or accidentally erase hosted data; it might also relegate it to slow or off-line storage.) The problem is exacerbated by the client being a small computing device with limited resources. Prior work has addressed this problem using either public key cryptography or requiring the client to outsource its data in encrypted form. Giuseppe Ateniese, Roberto Di Pietro, Luigi V. Mancini, Gene Tsudik |
SecureComm | 3 |
| 2008 | Emergent properties: detection of the node-capture attack in mobile wireless sensor networksabstractOne of the most vexing problems in wireless sensor network security is the node capture attack. An adversary can capture a node from the network as the first step for further different types of attacks. For example, the adversary can collect all the cryptographic material stored in the node. Also, the node can be reprogrammed and re-deployed in the network in order to perform malicious activities. To the best of our knowledge no distributed solution has been proposed to detect a node capture in a mobile wireless sensor network. In this paper we propose an efficient and distributed solution to this problem leveraging emergent properties of mobile wireless sensor networks. In particular, we introduce two solutions: SDD, that does not require explicit information exchange between the nodes during the local detection, and CCD, a more sophisticated protocol that uses local node cooperation in addition to mobility to greatly improve performance. We also introduce a benchmark to compare these solutions with. Experimental results demonstrate the feasibility of our proposal. For instance, while the benchmark requires about 9,000 seconds to detect node captures, CDD requires less than 2,000 seconds. These results support our intuition that node mobility, in conjunction with a limited amount of local cooperation, can be used to detect emergent global properties. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
WISEC | 3 |
| 2008 | Special Issue: Hot Topics in Peer-to-Peer SystemsabstractThis special issue of the journal Concurrency and Computation: Practice and Experience is intended to call further attention to Peer-to-Peer (P2P) systems. P2P systems are decentralized, self-organizing distributed systems that cooperate to exchange data. These systems have emerged as the dominant consumer of residential bandwidth, and are being increasingly used in many different application domains. In the last few years, research on P2P systems has been quite intensive, and has produced remarkable results in scalability, robustness, location, distributed storage, censorship resiliency, anonymity, and system measurements. Consequently, P2P systems continue to evolve, differentiating the state of the art from earlier instantiations such as file sharing. I believe that greater attention to these themes will be broadly enriching for concurrency and computation theory, research and application. The idea of organizing this special issue developed during the Hot-P2P '06, the third International Workshop on Hot Topics in Peer-to-Peer Systems, sponsored by the IEEE Computer Society and by the Italian FIRB ‘WEB–MINDS’ project (Wide scalE, Broadband MIddleware for Network Distributed Systems), held in Rhodes, Greece, on 29th April 2006. In this occasion, it was decided to add more visibility to the best papers and their institution. I took the responsibility to select eight papers which were required to provide substantial added contents and to pass further peer review. Hot-P2P '06 is an international meeting that brings together researchers and practitioners, from both industry and academia, in the fields of systems, networking, and theory. It represents an opportunity to share the latest research results and ideas on P2P systems, thereby promoting research activities in this area. The third edition of the workshop follows the first one, held on 8th October 2004 in Volendam (The Netherlands), and the second one, held on 21st July 2005 in San Diego (California). I would like to take this opportunity to thank the Editor-in-Chief Professor Geoffrey Fox for his guidance and support. I would also like to express my deepest gratitude to the invited reviewers for their valuable and timely reviews. Hence, together with the other contributing authors, I offer this special issue of the journal Concurrency and Computation: Practice and Experience devoted to Peer-to-Peer (P2P) systems. Luigi V. Mancini |
Concurr. Comput. Pract. Exp. | 1 |
| 2008 | Redoubtable Sensor NetworksabstractWe give, for the first time, a precise mathematical analysis of the connectivity and security properties of sensor networks that make use of the random predistribution of keys. We also show how to set the parameters---pool and key ring size---in such a way that the network is not only connected with high probability via secure links but also provably resilient, in the following sense: We formally show that any adversary that captures sensors at random with the aim of compromising a constant fraction of the secure links must capture at least a constant fraction of the nodes of the network. In the context of wireless sensor networks where random predistribution of keys is employed, we are the first to provide a mathematically precise proof, with a clear indication of parameter choice, that two crucial properties---connectivity via secure links and resilience against malicious attacks---can be obtained simultaneously. We also show in a mathematically rigorous way that the network enjoys another strong security property. The adversary cannot partition the network into two linear size components, compromising all the links between them, unless it captures linearly many nodes. This implies that the network is also fault tolerant with respect to node failures. Our theoretical results are complemented by extensive simulations that reinforce our main conclusions. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei, Alessandro Panconesi, Jaikumar Radhakrishnan |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2007 | Addressing interoperability issues in access control modelsabstractAccess control models need to be interoperable when administrative domains with heterogeneous access control models need to collaborate. Even, collaboration among homogeneous access control models is not straight-forward due to the different security orderings they might employ. In this paper, we briefly put forward an overlay formation mechanism based on chameleon hash functions. The mechanism allows collaborators to map their collaborating entities into a new collaboration specific security ordering that is agreeable to the peer collaborator. Collaborators use overlays as interoperation interfaces. By digitally signing each others' overlays, organizations enter into collaboration. Since overlays are virtual mappings, defining an overlay does not interfere with the access control model of the host organization. The use of overlays hides the internal security ordering of an organization from its collaborators. The trapdoor collision property of chameleon hash function ensures the privacy of collaboration agreements. Vishwas Patil, Alessandro Mei, Luigi V. Mancini |
AsiaCCS | 3 |
| 2007 | Towards threat-adaptive dynamic fragment replication in large scale distributed systemsabstractIn this paper, we consider new issues in building secure p2p file sharing systems. In particular, we define a powerful adversary model and consequently present the requirements to address when implementing a threat-adaptive secure file sharing system. We describe the main components of such a system: an early warning mechanism to perform pre-emptive actions against new vulnerabilities; a mechanism to sanitize corrupted nodes; a protocol to securely "migrate" data from non-safe nodes; and an efficient dynamic secret sharing mechanism. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
IPDPS | 2 |
| 2007 | A randomized, efficient, and distributed protocol for the detection of node replication attacks in wireless sensor networksabstractWireless sensor networks are often deployed in hostile environments, where anadversary can physically capture some of the nodes. Once a node is captured, the attackercan re-program it and replicate the node in a large number of clones, thus easily taking over the network. The detection of node replication attacks in a wireless sensor network is therefore a fundamental problem. A few distributed solutions have recently been proposed. However, these solutions are not satisfactory. First, they are energy and memory demanding: A serious drawback for any protocol that is to be used in resource constrained environment such as a sensor network. Further, they are vulnerable to specific adversary models introduced in this paper. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
MobiHoc | 3 |
| 2007 | ECCE: Enhanced cooperative channel establishment for secure pair-wise communication in wireless sensor networks
Mauro Conti, Roberto Di Pietro, Luigi V. Mancini |
Ad Hoc Networks | 3 |
| 2007 | Robust RSA distributed signatures for large-scale long-lived ad hoc networksabstractAd hoc environments are subject to tight security and architectural constraints, which call for distributed, adaptive, robust and efficient solutions. In this paper we propose a distributed signature protocol for large-scale long-lived ad hoc networks. The proposed protocol is based on RSA and a ne w (t,t)-secret sharing scheme. The nodes of the network are uniformly partitioned into t classes, and the nodes belonging to the same class are provided with the same share. Any t nodes, belonging to different classes, can collectively issue a signature, without any interaction. The scheme is at least as secure as any (t,n)-threshold scheme, i.e., an adversary can neither forge a signature nor disrupt the computation, unless it has compromised at least t nodes, belonging to different classes. Moreover, an attempt to disrupt the distributed service, by providing a fake signature share, would reveal the cheating node. Further, it is possible to easily increase the level of security, by shifting from a (t,t) to a (t+k,t+k) scheme, for a reasonable choice of parameter k, involving just a fraction of the nodes, so that the scheme is adaptive to the level of threat that the ad hoc network is subject to. Finally, the distributed signature protocol is efficient: the number of messages sent and received for generating a signature, as well as to increase the level of security, is small and both computations and memory required are small as well. Giorgio Zanin, Roberto Di Pietro, Luigi V. Mancini |
J. Comput. Secur. | 3 |
| 2006 | Addressing the shortcomings of one-way chainsabstractOne-way hash chains have been the preferred choice, over the symmetric and asymmetric key cryptography, in security setups where efficiency mattered; despite the ephemeral confidentiality and authentication they assure. Known constructions of one-way chains (for example, SHA-1 based), only ensure the forward secrecy and have limitations over their length i.e., a priori knowledge of chain's length is necessary before constructing it. In this paper, we will see how our approach, based on chameleon functions, leads to the generation of practically unbounded one-way chains with constant storage and computational requirements. We provide the construction and advantages of our proposal with the help of a secure group communication setup. We also provide the implementation details of our construction and argue its suitability for security setups, where one cannot a priori determine the longevity of the setup. Roberto Di Pietro, Luigi V. Mancini, Antonio Durante, Vishwas Patil |
AsiaCCS | 2 |
| 2006 | Scheduling Hard-Real-Time Tasks with Backup Phasing DelayabstractThis paper presents several fault-tolerant extensions of the Rate-Monotonic First-Fit multiprocessor scheduling algorithm handling both active and passive task copies. In particular, the technique of backup phasing delay is used to reduce the portions of active task copies that must be always executed and to deallocate active task copies as soon as their primary task copies have been successfully executed. It is also shown how to employ this technique while considering passive task duplication so as to over-book each processor with many passive task copies, assigning tasks to processors in such a way that tasks with equal or multiple periods have a high chance to be assigned to the same processor, and partitioning the processors into groups to avoid the mix of primary, active, and passive task copies on the same processor. Extensive simulations reveal a remarkable saving of both the overall number of processors used and the total computation time of the schedulability test (achieved especially by two new algorithms, called ARR3 and S-PR-PASS) with respect to previously proposed algorithms Alan A. Bertossi, Luigi V. Mancini, Alessandra Menapace |
DS-RT | 2 |
| 2006 | A Secure and Efficient Large Scale Distributed System for Data SharingabstractIn this paper we consider a large distributed system in which data is shared among several users. Specifically, we present a secure adaptive algorithm for data fragment allocation on multiple nodes of the system. The algorithm handles (replicated) data fragments, stored by nodes without the need of encryption, in such a way to ease information sharing. Data confidentiality is guaranteed in the presence of passive and active attacks, and fragments are dynamically reallocated/replicated in the system to converge, under assumptions of regularity of the read-write activity, to an allocation that provably guarantees highest performance in terms of network load. Giorgio Zanin, Alessandro Mei, Luigi V. Mancini |
ICDCS | 3 |
| 2006 | Requirements and Open Issues in Distributed Detection of Node Identity Replicas in WSNabstractWireless sensor networks (WSN) are often deployed in hostile environments, where an attacker can also capture some nodes. Once a node is captured, the attacker can re-program it and start replicating the node. These replicas can then be deployed in all (or a part of) the network area. The replicas can thus perform the attack they are programmed for: DoS (Denial of Service), or influencing any voting mechanism are just examples. Detection of node replication attack is therefore a fundamental property of all the WSN applications in which an attacker presence is possible. The contribution of this paper is twofold: First, we analyze the desirable properties of a distributed mechanism for the detection of replicated IDs; second, we show that the first proposal recently appeared in literature to realize a distributed solution for the detection of replicas does not completely fulfil the requirements. Hence, the design of efficient and distributed protocols to detect node identity replicas is still an open and demanding issue. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
SMC | 3 |
| 2006 | Energy efficient node-to-node authentication and communication confidentiality in wireless sensor networks
Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
Wirel. Networks | 2 |
| 2005 | Securing Topology Maintenance Protocols for Sensor NetworksabstractWe analyze the security vulnerabilities of PEAS, ASCENT, and CCP, three well-known topology maintenance protocols for sensor networks. These protocols aim to increase the lifetime of the sensor network by maintaining only a subset of nodes in an active or awake state. The design of these protocols assumes that the sensor nodes will be deployed in a trusted non-adversarial environment, and does not take into account the impact of attacks launched by malicious insider and outsider nodes. We describe three attacks against these protocols that can be used to reduce the lifetime of the sensor network, or to degrade the functionality of the sensor application by reducing the network connectivity and sensing coverage that can be achieved. Further, we describe counter-measures that can be used to increase the robustness of the protocols and make them resilient to such attacks. Andrea Gabrielli, Luigi V. Mancini, Sanjeev Setia, Sushil Jajodia |
SecureComm | 2 |
| 2005 | Short Paper: Practically Unbounded One-Way Chains for Authentication with Backward SecrecyabstractOne-way hash chains have been the preferred choice (over symmetric and asymmetric key cryptography) in security setups where efficiency mattered; despite the ephemeral confidentiality and authentication they assure. They only support forward secrecy and have limitations over the chain size (bounded). In this paper, we show how the use of chameleon functions leads to the generation of practically unbounded one-way chains with constant memory storage requirement, providing forward, and backward secrecy as well. Such a cryptographic tool appears to be a great enabler for a variety of applications that could not be efficiently realized earlier. From our experiments we observed that this new kind of one-way chain formation adds a slight computational burden, which is justifiable by the unique advantages provided under our construction. The basic unit of our construction, chameleon function, can be elegantly used to design trees or even simpler star-like constructs Roberto Di Pietro, Antonio Durante, Luigi V. Mancini, Vishwas Patil |
SecureComm | 3 |
| 2005 | Graph-based specification of access control policies
Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
J. Comput. Syst. Sci. | 2 |
| 2004 | Information Flow Analysis for File Systems and Databases Using LabelsabstractThe control of information flow has been used to address problems concerning the privacy and the secrecy of data. A model based on decentralized labels extends traditional multilevel security models by allowing users to declassify information in a distributed way. We extend this decentralized labels model developed by other authors by addressing specific issues that arise in accessing files and databases and in general in I/O operations. While retaining the support for static analysis, we also include run-time checks to allow declassification with “controlled information leakage”. Ehud Gudes, Luigi V. Mancini, Francesco Parisi-Presicce |
DBSec | 2 |
| 2004 | A Host Intrusion Prevention System for Windows Operating Systems
Roberto Battistoni, Emanuele Gabrielli, Luigi V. Mancini |
ESORICS | 3 |
| 2004 | Efficient and Resilient Key Discovery Based on Pseudo-Random Key Pre-DeploymentabstractSummary form only given. A distributed wireless sensor network (WSN) is a collection of n sensors with limited hardware resources and multihop message exchange capabilities. Due to the scarceness of resources, the distributed paradigm required, and the threats to the security, a challenging problem is how to implement secure pair-wise communications among any pair of sensors in a WSN. In particular, storage memory and energy saving as well as resilience to physical compromising of a sensor are the more stringent requirements. The contributions are twofold: (1) we describe a new threat model to communications confidentiality in WSNs (the smart attacker model); under this new, more realistic threat model, the security features of the previous schemes proposed in the literature drastically decrease; (2) we provide a new pseudo-random key predeployment strategy that assures: (a) a key discovery phase that requires no communications; (b) high resilience against the smart attacker model. We provide both analytical evaluations and extensive simulations of the proposed scheme. The results indicate that our pseudo-random key predeployment proposal achieves a provably efficient assignment of keys to sensors, an energy preserving key discovery phase, and is resilient against the smart attacker model. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
IPDPS | 2 |
| 2004 | Administrative scope in the graph-based frameworkabstractThe use of the graph-based framework to specify the administration of RBAC systems has several advantages, from the intuition provided by the visual aspect to the precise semantics and the systematic verification of constraints. Here the benefits of this framework are illustrated using SARBAC (scoped administration of role based access control), providing the first steps towards its operational semantics and a more expressive constraint language. Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
SACMAT | 2 |
| 2004 | Towards a formal model for security policies specification and validation in the selinux systemabstractThis paper presents a formal model, called SELAC, for analyzing an arbitrary security policy configuration for the SELinux system. A security policy for SELinux is complex and large: it is made by many configuration rules that refer to the access control sub-models implemented in the system. Among the rules composing a security policy configuration, many relationships occur and it is extremely difficult to understand their overall effects in the system. Our aim is to define semantics for the constructs of the SELinux configuration language and to model the relationships occurring among sets of configuration rules. Finally, we develop an algorithm based upon SELAC, which can verify whether, given an arbitrary security policy configuration, a given subject can access a given object in a given mode. Giorgio Zanin, Luigi V. Mancini |
SACMAT | 2 |
| 2004 | Key management for high bandwidth secure multicastabstractThis paper brings up a new concern regarding efficient re-keying of large groups with dynamic membership: minimizing the overall time it takes for the key server and the group members to process the re-keying message. Specifically, we concentrate on re-keying algorithms based on the Logical Key Hierarchy (LKH), and minimize the longest sequence of encryptions and decryptions that need to be done in a re-keying operation. We first prove a lower bound on the time required to perform a re-keying operation in this model, then we provide an optimal schedule of re-keying messages matching the above lower bound. In particular, we show that the optimal schedule can be found only when the ariety of the LKH key graph is chosen according to the available communication bandwidth and the users processing power. Our results show that key trees of ariety 3, commonly assumed to be optimal, are not optimal when used in high bandwidth networks, or networks of devices with low computational power like sensor networks. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
J. Comput. Secur. | 2 |
| 2003 | A Time Driven Methodology for Key Dimensioning in Multicast Communications
Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
SEC | 2 |
| 2003 | A Reliable Key Authentication Schema for Secure Multicast CommunicationsabstractThe paper analyzes the Logical Key Hierarchy (LKH) secure multicast protocol focusing on the reliability of the re-keying authentication process. We show that the key management in the LKH model is subject to some attacks. In particular, these attacks can be performed by entities external to the multicast group, as well as from internal users of the multicast group. The spectrum of these attacks is spread from the denial of service (DoS) to the session hijack that is the attacker is able to have legitimate users to commit on a session key that is provided by the attacker. The contributions of this paper are: (1) the definition of the threats the LKH key management is subject to; and (2) a reliable key authentication scheme that solves the weaknesses previously identified. This objective is achieved without resorting to public key signatures. Roberto Di Pietro, Antonio Durante, Luigi V. Mancini |
SRDS | 3 |
| 2003 | Providing secrecy in key management protocols for large wireless sensors networks
Roberto Di Pietro, Luigi V. Mancini, Sushil Jajodia |
Ad Hoc Networks | 2 |
| 2003 | Secure Dynamic Fragment and Replica Allocation in Large-Scale Distributed File SystemsabstractWe present a distributed algorithm for file allocation that guarantees high assurance, availability, and scalability in a large distributed file system. The algorithm can use replication and fragmentation schemes to allocate the files over multiple servers. The file confidentiality and integrity are preserved, even in the presence of a successful attack that compromises a subset of the file servers. The algorithm is adaptive in the sense that it changes the file allocation as the read-write patterns and the location of the clients in the network change. We formally prove that, assuming read-write patterns are stable, the algorithm converges toward an optimal file allocation, where optimality is defined as maximizing the file assurance. Alessandro Mei, Luigi V. Mancini, Sushil Jajodia |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2002 | Decidability of Safety in Graph-Based Models for Access Control
Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
ESORICS | 2 |
| 2002 | Conflict Detection and Resolution in Access Control Policy Specifications
Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
FoSSaCS | 2 |
| 2002 | Secure Selective Exclusion in Ad Hoc Wireless Network
Roberto Di Pietro, Luigi V. Mancini, Sushil Jajodia |
SEC | 2 |
| 2002 | Remus: a security-enhanced operating systemabstractWe present a detailed analysis of the UNIX system calls and classify them according to their level of threat with respect to system penetration. Based on these results, an effective mechanism is proposed to control the invocation of critical, from the security viewpoint, system calls. The integration into existing UNIX operating systems is carried out by instrumenting the code of the system calls in such a way that the execution is granted only in the case where the invoking process and the value of the arguments comply with the rules held in an access control database. This method does not require changes in the kernel data structures and algorithms. All kernel modifications are transparent to the application processes that continue to work correctly with no need of source code changes or recompilation. A working prototype has been implemented as a loadable kernel module for the Linux operating system. The prototype is able to detect and block any attacks by which an intruder tries to gain direct access to the system as a privileged user. Massimo Bernaschi, Emanuele Gabrielli, Luigi V. Mancini |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2002 | A graph-based formalism for RBACabstractRole-Based Access Control (RBAC) is supported directly or in a closely related form, by a number of products. This article presents a formalization of RBAC using graph transformations that is a graphical specification technique based on a generalization of classical string grammars to nonlinear structures. The proposed formalization provides an intuitive description for the manipulation of graph structures as they occur in information systems access control and a precise specification of static and dynamic consistency conditions on graphs and graph transformations. The formalism captures the RBAC models published in the literature, and also allows a uniform treatment of user roles and administrative roles, and a detailed analysis of the decentralization of administrative roles. Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2001 | Foundations for a Graph-Based Approach to the Specification of Access Control Policies
Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
FoSSaCS | 2 |
| 2001 | On the specification and evolution of access control policiesabstractA uniform and precise framework for the specification of access control policies is proposed. The uniform framework allows the detailed comparison of different policy models, the precise description of the evolution of a policy, and an accurate analysis of the interaction between policies and of the behavior of their integration. The evolution and integration of policies are illustrated using a Discretionary Access Control policy and a Lattice Based Access Control policy. The framework is based on the theory of graph transformations. Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
SACMAT | 2 |
| 2000 | Operating system enhancements to prevent the misuse of system callsabstractWe propose a cost-effective mechanism, to control the invocation of critical, from the security viewpoint, system calls. The integration into existing UNIX operating systems is carried out by instrumenting the code of the system calls so that the system call itself once invoked checks to see whether the invoking process and the argument values passed comply with the rules held in an access control database. This method provides simple interception of both system calls and their argument values and do not require changes in the kernel data structures and algorithms. All kernel modifications are transparent to the application processes that can continue to work correctly without needing changes of the source code or re-compilation. A working prototype has been implemented inside the kernel of the Linux operating system, the prototype is able to detect and block also buffer overflow based attacks. Massimo Bernaschi, Emanuele Gabrielli, Luigi V. Mancini |
CCS | 3 |
| 2000 | A Formal Model for Role-Based Access Control Using Graph Transformation
Manuel Koch, Luigi V. Mancini, Francesco Parisi-Presicce |
ESORICS | 2 |
| 2000 | Flexible Transaction Dependencies in Database Systems
Luigi V. Mancini, Indrajit Ray, Sushil Jajodia, Elisa Bertino |
Distributed Parallel Databases | 1 |
| 2000 | ASEP: A Secure and Flexible Commit Protocol for MLS Distributed Database SystemsabstractThe classical Early Prepare (EP) commit protocol, used in many commercial systems, is not suitable for use in multi-level secure (MLS) distributed database systems that employ a locking protocol for concurrency control. This is because EP requires that read locks are not released by a participant during their window of uncertainty; however, it is not possible for a locking protocol to provide this guarantee in a MLS system (since the read lock of a higher-level transaction on a lower-level data object must be released whenever a lower-level transaction wants to write the same data). The only available work in the literature, namely the Secure Early Prepare (SEP) protocol, overcomes this difficulty by aborting those distributed transactions that release their low-level read locks prematurely. We see this approach as being too restrictive. One of the major benefits of distributed processing is its robustness to failures, and SEP fails to take advantage of this. In this paper, we propose the Advanced Secure Early Prepare (ASEP) commit protocol to solve the above problem, together with a number of language primitives that can be used as system calls in distributed transactions. These primitives permit features like partial rollback and forward recovery to be incorporated within the transaction model, and allow a distributed transaction to proceed even when a participant has released its low-level read locks prematurely. This not only offers flexibility, but can also be used, if desired, by a sophisticated programmer to trade off consistency for atomicity of the distributed transaction. Indrajit Ray, Luigi V. Mancini, Sushil Jajodia, Elisa Bertino |
IEEE Trans. Knowl. Data Eng. | 2 |
| 1999 | Fault-Tolerant Rate-Monotonic First-Fit Scheduling in Hard-Real-Time SystemsabstractHard-real-time systems require predictable performance despite the occurrence of failures. In this paper, fault tolerance is implemented by using a novel duplication technique where each task scheduled on a processor has either an active backup copy or a passive backup copy scheduled on a different processor. An active copy is always executed, while a passive copy is executed only in the case of a failure. First, the paper considers the ability of the widely-used rate-monotonic scheduling algorithm to meet the deadlines of periodic tasks in the presence of a processor failure. In particular, the completion time test is extended so as to check the schedulability on a single processor of a task set including backup copies. Then, the paper extends the well-known rate-monotonic first-fit assignment algorithm, where all the task copies, included the backup copies, are considered by rate-monotonic priority order and assigned to the first processor in which they fit. The proposed algorithm determines which tasks must use the active duplication and which can use the passive duplication. Passive duplication is preferred whenever possible, so as to overbook each processor with many passive copies whose primary copies are assigned to different processors. Moreover, the space allocated to active copies is reclaimed as soon as a failure is detected. Passive copy overbooking and active copy deallocation allow many passive copies to be scheduled sharing the same time intervals on the same processor, thus reducing the total number of processors needed. Simulation studies reveal a remarkable saving of processors with respect to those needed by the usual active duplication approach in which the schedule of the non-fault-tolerant case is duplicated on two sets of processors. Alan A. Bertossi, Luigi V. Mancini, Federico Rossini |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 1998 | A Fair Locking Protocol for Multilevel Secure DatabasesabstractMost concurrency control algorithms for multilevel secure databases based on kernelized architecture prevent covert channels between transactions at different security levels by preempting the high security transaction in the event of a data conflict with a lower security transaction. In environments with moderate to high levels of contention between low and high security transactions, this can lead to poor performance and even starvation of high security transactions. We examine this problem of unfairness in concurrency control mechanisms for secure databases. Based on an analysis of the performance of a secure version of two phase locking, we propose three different modifications to the protocol that address the problem of starvation of high security transactions. Through a detailed simulation study, we examine the fairness and performance of these approaches for a variety of workloads. Sushil Jajodia, Luigi V. Mancini, Sanjeev Setia |
CSFW | 2 |
| 1998 | Advanced Transaction Processing in Multilevel Secure File StoresabstractThe concurrency control requirements for transaction processing in a multilevel secure file system are different from those in conventional transaction processing systems. In particular, there is the need to coordinate transactions at different security levels avoiding both potential timing covert channels and the starvation of transactions at higher security levels. Suppose a transaction at a lower security level attempts to write a data item that is being read by a transaction at a higher security level. On the one hand, a timing covert channel arises if the transaction at the lower security level is either delayed or aborted by the scheduler. On the other hand, the transaction at the high security level may be subjected to an indefinite delay if it is forced to abort repeatedly. This paper extends the classical two-phase locking mechanism to multilevel secure file systems. The scheme presented here prevents potential timing covert channels and avoids the abort of higher level transactions nonetheless guaranteeing serializability. The programmer is provided with a powerful set of linguistic constructs that supports exception handling, partial rollback, and forward recovery. The proper use of these constructs can prevent the indefinite delay in completion of a higher level transaction, and allows the programmer to trade off starvation with transaction isolation. Elisa Bertino, Sushil Jajodia, Luigi V. Mancini, Indrajit Ray |
IEEE Trans. Knowl. Data Eng. | 3 |
| 1997 | Two Implementation Relations and the Correctness of Communicating Replicated ProcessesabstractAbstract This paper studies the correctness of distributed systems made up of replicated processes that communicate by message passing. Processes are described within the divergence model of CSP. The notion of correctness introduced is based on a relation that formally expresses the conformance of an implementation process with the target process it is intended to implement. A weak and a strong version of the relation are introduced, aimed at treating acyclic and cyclic process networks respectively. Both allow the study of (total) correctness and may cope with non-deterministic targets and implementations. We then show how a target process may be implemented (in the formal sense introduced) by replicating it in a set of copies, a majority of which is non-faulty. Maciej Koutny, Luigi V. Mancini, Giuseppe Pappalardo |
Formal Aspects Comput. | 2 |
| 1996 | An Advanced Commit Protocol for MLS Distributed Database SystemsabstractThe classical Early Prepare commit protocol (EP), used in many commercial systems, is not suitable for use in multilevel secure distributed database systems that employ a locking protocol for concurrency control. This is because EP requires that read locks be not released by a subtransaction during its window of uncertainty; however, it is not possible for a locking protocol to provide this guarantee in a multilevel secure system (since read lock of a higher level transaction on a lower level data object must be released whenever a lower level transaction wants to write it). The Secure Early Prepare protocol (SEP) overcomes this difficulty by aborting those distributed transactions that release their low level read locks prematurely. We see this approach as being too restrictive. One of the major benefits of distributed processing is its robustness to failures, and SEP fails to take advantage of this. In this work, we propose the Advanced Secure Early Prepare commit protocol (ASEP) to... Indrajit Ray, Elisa Bertino, Sushil Jajodia, Luigi V. Mancini |
CCS | 4 |
| 1996 | Secure Locking Protocols for Multilevel Database Management Systems
Sushil Jajodia, Luigi V. Mancini, Indrajit Ray |
DBSec | 2 |
| 1996 | Secure Concurrency Control in MLS Databases with Two Versions of Data
Luigi V. Mancini, Indrajit Ray |
ESORICS | 1 |
| 1995 | Increasing Processor Utilization in Hard-Real-Time Systems with Checkpoints
Alan A. Bertossi, Massimo Bonometto, Luigi V. Mancini |
Real Time Syst. | 3 |
| 1994 | Mark-and-Sweep Garbage Collection in Multilevel Secure Object-Oriented Database Systems
Alessandro Ciampichetti, Elisa Bertino, Luigi V. Mancini |
ESORICS | 3 |
| 1994 | Collecting garbage in multilevel secure object storesabstractThis paper addresses the problem of garbage collection in persistent object stores that are multilevel. The proposed approach is able to preserve referential integrity, while ensuring that security is not violated. we first discuss some general principles that should underlie any approach to garbage collection in secure environments. Then, we present a secure garbage collection algorithm, based on the copying approach.> Elisa Bertino, Luigi V. Mancini, Sushil Jajodia |
S&P | 2 |
| 1994 | Scheduling Algorithms for Fault-Tolerance in Hard-Real-Time Systems
Alan A. Bertossi, Luigi V. Mancini |
Real Time Syst. | 2 |
| 1993 | The Duality of Fault-tolerant System StructuresabstractAbstract An examination of the structure of fault‐tolerant systems incorporating backward error recovery indicates a partitioning into two broad classes. Two canonical models, each representing a particular class of systems, have been constructed. The first model incorporates objects and actions as the entities for program construction whereas the second model employs communicating processes and conversations. Applications in areas such as office information and banking systems are typically described and built in terms of the first model whereas applications in the area of process control are usually described and built in terms of the second model. The paper claims that the two models are duals of each other and presents arguments and examples to substantiate this claim. It will be shown that the techniques that have been developed within the context of one model turn out to have interesting and hitherto unexplored duals in the other model. Santosh K. Shrivastava, Luigi V. Mancini, Brian Randell |
Softw. Pract. Exp. | 2 |
| 1991 | Formalising Replicated Distributed ProcessingabstractThe authors present a novel formal approach to proving the correctness of distributed systems of replicated processes that communicate by message passing. The notion of correctness introduced is based on the consistency of the replicated system with its nonreplicated counterpart. The formal framework of CSP (communicating sequential processes) allows the proof of partial correctness and deadlock-freedom properties of the systems of replicated processes. The authors also discuss how a replicated process may be implemented by N-base copies, a majority of which are non-faulty, and point out the necessity of coordinating the copies and the requirements they should satisfy.> Maciej Koutny, Luigi V. Mancini, Giuseppe Pappalardo |
SRDS | 2 |
| 1991 | Copying Garbage Collection for Distributed Object StoresabstractThe authors describe a garbage collection scheme for managing a distributed object store in which accessible objects survive system failures. The scheme is based on copying garbage collection and has the following advantages: it is tolerant to node failures, a fail-stop behavior of the node is assumed; it is partial, a given execution of the distributed garbage collection does not need to involve all the nodes, that is, the garbage collector can collect garbage on a subset of the entire system nodes; it minimizes disk accesses; it can collect any kind of cycles both within a node and among different nodes; it uses the depth-first-search to increase locality; it is iterative and it does not assume any particular primitives of the operating system of a node. In addition this distributed garbage collector can be extended to be asynchronous, that is, every node can decide to begin the collection at any time independently of the others.> Luigi V. Mancini, Vittoria Rotella, Simonetta Venosa |
SRDS | 1 |
| 1991 | Fault-Tolerant Reference Counting for Garbage Collection in Distributed SystemsabstractThe function of a garbage collector in a computer system is to reclaim storage that is no longer in use. Developing a garbage collector for a distributed system composed of autonomous computers (nodes) connected by a communication network poses a challenging problem: optimising performance whilst achieving fault-tolerance. The paper presents the design and implementation of a reference-count garbage collection scheme which is both efficient and fault-tolerant. A distributed object-based system is considered where operations on remote objects are invoked via remote procedure calls. The orphan treatment scheme associated with remote procedure calls has been enhanced to enable the collection of garbage arising from node crashes. Luigi V. Mancini, Santosh K. Shrivastava |
Comput. J. | 1 |
| 1989 | Proving Correctness Properties of a Replicated Synchronous ProgramabstractReplicated synchronous programs executed by a set of possibly faulty processors find a natural application in the fault-tolerance technique known as N-Modular Redundancy (NMR). We present an axiomatic approach to correctness proofs for replicated synchronous programs and illustrate its application by studying an agreement protocol for NMR distributed computing. Luigi V. Mancini, Giuseppe Pappalardo |
Comput. J. | 1 |
| 1989 | Synchronizing events in replicated systems
Maciej Koutny, Luigi V. Mancini |
J. Syst. Softw. | 2 |
| 1988 | A Technique for Subclassing and its Implementation Exploiting Polymorphic ProceduresabstractAbstract Since the introduction of Smalltalk, the object‐oriented approach towards the organization of data and programs has become popular. In this paper the possibilities of exploiting procedure‐oriented languages to allow an object‐oriented style of programming are analysed. Although the two approaches are apparently dissimilar, a family of procedure‐oriented languages is described which allows a high degree of freedom in programming and does not appear to restrain the programmer within the procedure‐oriented scheme. Popular languages of this family are ML and PS‐Algol. For such languages, a technique is developed which enables an efficient implementation of object‐oriented features, such as the subclassing form of inheritance provided by Smalltalk‐80 and Simula. Luigi V. Mancini |
Softw. Pract. Exp. | 1 |
| 1986 | Modular Redundancy in a Message Passing SystemabstractModular redundancy in the form of replicated computations in a concurrent programming model consisting of communicating sequential processes is investigated. Some conditions are given which must always be verified to ensure correctness in the presence of nondeterminism. Then some implementations which satisfy the given conditions are proposed. This approach permits redundant systems to be robust with respect to failures in redundant processors, and also permits the use of software fault tolerance techniques such asN-version programming. The concurrent programming model which has been chosen is based on a set of active entities, i.e. processes, each running in a local protected environment. The processes interact using message passing only. Luigi V. Mancini |
IEEE Trans. Software Eng. | 1 |