Clemente Galdi

dblp:64/6932 · DBLP profile ↗
← Back
32ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0002-2988-700XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 2 first-author · 2 since 2021Theory of computation · 7 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3Software engineering, systems software and programming languages · 2Graphics, computer vision, multimedia, augmented reality and games · 2Artificial intelligence and machine learning · 1Computer networks · 1
YearPublicationVenuePosition
2024 Special Issue on 13th International Conference on Security and Cryptography for Networks (SCN 2022)
Clemente Galdi, Stanislaw Jarecki
Inf. Comput.1
2022 On Tracking Ransomware on the File System
Luigi Catuogno, Clemente Galdi
ICISSP2
2022 Special issue: Security and Cryptography for Networks - SCN 2020
Clemente Galdi, Vladimir Kolesnikov
J. Comput. Secur.1
2020 Secure Dependency Enforcement in Package Management Systems
abstract
Package management systems play an essential role in pursuing systems dependability by ensuring that software is correctly installed and kept up-to-date according to vendor-defined installation policies. Circumventing such policies could make the system unhealthy and insecure and can constitute a serious security threat. In many application scenarios, e.g., distribution of commercial software, the confidentiality of the software must be guaranteed against non-authorized players. In some cases, the installation policy itself is considered a sensitive information, e.g., when it reveals required hardware in military contexts. In this paper we address the problem of strongly enforcing software dependencies in package management systems, to prevent that a malicious user forces the system to install any package despite its requirements are not completely fulfilled. The enforcement is strong in the sense that the encrypted software package cannot be even decrypted if the dependencies are not satisfied. Once a new package is decrypted and installed, our protocol non-interactively updates the key material on the target device. This key update will allow the decryption of further packages that depend on the newly installed one. We further present “policy-hiding” variants of our protocol. Finally we provide an experimental evaluation of the system performance.
Luigi Catuogno, Clemente Galdi, Giuseppe Persiano
IEEE Trans. Dependable Secur. Comput.2
2019 A Fine-grained General Purpose Secure Storage Facility for Trusted Execution Environment
abstract
In this paper we address the problem of enforcing data access control over the storage area of a mobile device running different and independent third party applications. To this end, we present the design of a general purpose secure file system that allows to guarantee file-grained data confidentiality at OS level. Data encryption, key management and policy enforcement are based on Trusted Execution Environment (TEE) facilities. We describe a prototype implementation and discuss preliminary performance results.
Luigi Catuogno, Clemente Galdi
ICISSP2
2017 Information Retention in Heterogeneous Majority Dynamics
Vincenzo Auletta, Ioannis Caragiannis, Diodato Ferraioli, Clemente Galdi, Giuseppe Persiano
WINE4
2017 Recommendation in museums: paths, sequences, and group satisfaction maximization
Silvia Rossi 0002, Francesco Barile, Clemente Galdi, Luca Russo
Multim. Tools Appl.3
2016 Generalized Discrete Preference Games
Vincenzo Auletta, Ioannis Caragiannis, Diodato Ferraioli, Clemente Galdi, Giuseppe Persiano
IJCAI4
2016 Flexible and robust Enterprise Right Management
abstract
This paper presents and discusses an Enterprise Rights Management System (ERM) tailored for remote maintenance facilities which features secure on-site documentation storage and availability, strong data provider control over access policy and their enforcement, minimal documentation disclosure and strong and ergonomic operator authentication by means of biometric measurements. The design approach pursues the technological neutrality with respect to the documentation format and operator side equipments.
Luigi Catuogno, Clemente Galdi, Daniel Riccio
ISCC2
2015 Minority Becomes Majority in Social Networks
abstract
It is often observed that agents tend to imitate the behavior of their neighbors in a social network. This imitating behavior might lead to the strategic decision of adopting a public behavior that differs from what the agent believes is the right one and this can subvert the behavior of the population as a whole. In this paper, we consider the case in which agents express preferences over two alternatives and model social pressure with the majority dynamics: at each step an agent is selected and its preference is replaced by the majority of the preferences of her neighbors. In case of a tie, the agent does not change her current preference. A profile of the agents’ preferences is stable if the each agent’s preference coincides with the preference of at least half of the neighbors (thus, the system is in equilibrium). We ask whether there are network topologies that are robust to social pressure. That is, we ask whether there are graphs in which the majority of preferences in an initial profile $${\mathbf {s}}$$ always coincides with the majority of the preference in all stable profiles reachable from $${\mathbf {s}}$$ . We completely characterize the graphs with this robustness property by showing that this is possible only if the graph has no edge or is a clique or very close to a clique. In other words, except for this handful of graphs, every graph admits at least one initial profile of preferences in which the majority dynamics can subvert the initial majority. We also show that deciding whether a graph admits a minority that becomes majority is NP-hard when the minority size is at most 1 / 4-th of the social network size.
Vincenzo Auletta, Ioannis Caragiannis, Diodato Ferraioli, Clemente Galdi, Giuseppe Persiano
WINE4
2015 Event-driven RBAC
abstract
Context-aware access control systems should reactively adapt access control decisions to dynamic environmental conditions. In this paper we present ERBAC – an event-driven extension of the TRBAC model that allows the specification and enforcement of general reactive policies – and its implementation. While almost all the individual features of ERBAC occur separately in some previous model, the detailed design of the policy language, its implementation in XACML, and its testing contribute to the development of expressive, event-driven policy frameworks by demonstrating that this rich model can be satisfactorily implemented, and that its expressivity and performance are compatible with a variety of realistic application scenarios. In particular, a number of examples illustrate ERBAC’s expressive power, and its ability of handling exceptional situations in a flexible way, while keeping policies compact and manageable. The prototype extends XACML’s language and the implementation of the PDP to support the new model. Systematic scalability experiments show that the computational cost of policy rule evaluation in ERBAC is compatible with real-world applications.
Piero A. Bonatti, Clemente Galdi, Davide Torres
J. Comput. Secur.2
2014 Optimality and Complexity of Inference-Proof Data Filtering and CQE
Joachim Biskup, Piero A. Bonatti, Clemente Galdi, Luigi Sauro
ESORICS (2)3
2013 Auctions for Partial Heterogeneous Preferences
Piero A. Bonatti, Marco Faella, Clemente Galdi, Luigi Sauro
MFCS3
2013 ERBAC: event-driven RBAC
abstract
Context-aware access control systems should reactively adapt access control decisions to dynamic environmental conditions. In this paper we present an extension of the TRBAC model that allows the specification and enforcement of general reactive policies. Then we extend XACML to support the new model, and illustrate a prototype implementation of the PDP.
Piero A. Bonatti, Clemente Galdi, Davide Torres
SACMAT2
2013 Certified Information Access
Carlo Blundo, Angelo De Caro, Clemente Galdi, Giuseppe Persiano
J. Syst. Softw.3
2011 Towards a Mechanism for Incentivating Privacy
Piero A. Bonatti, Marco Faella, Clemente Galdi, Luigi Sauro
ESORICS3
2010 On the Security of a Two-Factor Authentication Scheme
Luigi Catuogno, Clemente Galdi
WISTP2
2009 Hypergraph decomposition and secret sharing
Giovanni Di Crescenzo, Clemente Galdi
Discret. Appl. Math.2
2008 A Distributed Implementation of the Certified Information Access Service
Carlo Blundo, Emiliano De Cristofaro, Aniello Del Sorbo, Clemente Galdi, Giuseppe Persiano
ESORICS4
2008 A Graphical PIN Authentication Mechanism with Applications to Smart Cards and Low-Cost Devices
Luigi Catuogno, Clemente Galdi
WISTP2
2007 Distributed Certified Information Access for Mobile Devices
Aniello Del Sorbo, Clemente Galdi, Giuseppe Persiano
WISTP2
2006 Neural Network Techniques for Proactive Password Checking
abstract
This paper deals with the access control problem. We assume that valuable resources need to be protected against unauthorized users and that, to this aim, a password-based access control scheme is employed. Such an abstract scenario captures many applicative settings. The issue we focus our attention on is the following: password-based schemes provide a certain level of security as long as users choose good passwords, i.e., passwords that are hard to guess in a reasonable amount of time. In order to force the users to make good choices, a proactive password checker can be implemented as a submodule of the access control scheme. Such a checker, any time the user chooses/changes his own password, decides on the fly whether to accept or refuse the new password, depending on its guessability. Hence, the question is: how can we get an effective and efficient proactive password checker? By means of neural networks and statistical techniques, we answer the above question, developing suitable proactive password checkers. Through a series of experiments, we show that these checkers have very good performance: error rates are comparable to those of the best existing checkers, implemented on different principles and by using other methodologies, and the memory requirements are better in several cases. It is the first time that neural network technology has been fully and successfully applied to designing proactive password checkers
Angelo Ciaramella, Paolo D'Arco, Alfredo De Santis, Clemente Galdi, Roberto Tagliaferri
IEEE Trans. Dependable Secur. Comput.4
2005 Design and Implementation of an Inline Certified E-mail Service
Stelvio Cimato, Clemente Galdi, Raffaella Giordano, Barbara Masucci, Gildo Tomasco
CANS2
2005 Basic Computations in Wireless Networks
Ioannis Caragiannis, Clemente Galdi, Christos Kaklamanis
ISAAC2
2005 Network Load Games
Ioannis Caragiannis, Clemente Galdi, Christos Kaklamanis
ISAAC2
2004 Certified E-Mail with Temporal Authentication: An Improved Optimistic Protocol
Clemente Galdi, Raffaella Giordano
TrustBus1
2004 HYPPOCRATES: a new proactive password checker
Carlo Blundo, Paolo D'Arco, Alfredo De Santis, Clemente Galdi
J. Syst. Softw.4
2003 Hypergraph Decomposition and Secret Sharing
Giovanni Di Crescenzo, Clemente Galdi
ISAAC2
2003 Hiding Information in Image Mosaics
abstract
Information hiding techniques allow a player to hide secret information in some innocent-looking document. In this paper we present a novel approach to information hiding. We investigate the possibility of embedding information using the intrinsic entropy of some classes of cover-documents. In particular we provide algorithms for embedding any binary string in an image mosaic (i.e. an image consisting of a mosaic of smaller images). The algorithms presented allow different levels of security for the information hidden in the cover-document. We also show some techniques to reduce the amount of information the users have to secretly store.
Carlo Blundo, Clemente Galdi
Comput. J.2
2001 Hyppocrates
Carlo Blundo, Paolo D'Arco, Alfredo De Santis, Clemente Galdi
ISC4
2001 Optimal and Approximate Station Placement in Networks (With Applications to Multicasting and Space Efficient Traversals)
Clemente Galdi, Christos Kaklamanis, Manuela Montangero, Giuseppe Persiano
STACS1
1999 Randomness Recycling in Constant-Round Private Computations (extended Abstract)
Carlo Blundo, Clemente Galdi, Giuseppe Persiano
DISC2