VLDB 2026 Research / reviewers in the wild / expert
Roberto Di Pietro
dblp:73/6934
· DBLP profile ↗
180ranked-venue papers
54as first author
52since 2021 · last 2026
0000-0003-1909-0336ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 92 · 26 first-author · 27 since 2021Computer networks · 52 · 17 first-author · 15 since 2021Systems, architecture and hardware · 12 · 7 first-author · 4 since 2021Artificial intelligence and machine learning · 9 · 2 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 6 · 5 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 first-authorTheory of computation · 4Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From DePIN Hype to Operational Reality: Assessing Centralization and Usage of Commercial dVPNsabstractDecentralized VPNs (dVPNs) are marketed as a flagship use case of Decentralized Physical Infrastructure Networks (DePIN): a fully decentralized, censorship-resistant alternative to traditional VPNs, where users route traffic through a global pool of independently operated exit nodes. However, despite claims of decentralization and “military-grade privacy”, little is known in both the white and the gray literature about the actual commercial dVPNs architecture, their true level of decentralization, and what they are used for. To fill these gaps, in this work, we present the first data-driven, operator-centric study of commercial dVPNs. We deploy several fully functional exit nodes worldwide on two prominent dVPN platforms, Mysterium and Sentinel. Via such nodes, we collect control-plane traffic, user traffic, and publicly available metadata to assess what an honest-but-curious operator can infer about systems' architecture, effective decentralization, and real-world usage. Our findings challenge the dominant narrative. Architecturally, both investigated dVPNs rely heavily on centralized orchestrators, often hosted on a handful of Cloud providers. These components constitute clear chokepoints, making the networks more fragile, censorable, and way less decentralized than their branding suggests. From a usage perspective, traffic relayed by our nodes is dominated by mainstream, commercially oriented activities rather than by censorship evasion or privacy-motivated uses. Overall, we show that current commercial dVPNs inherit many centralized features of traditional VPNs while shifting trust and liability onto a heterogeneous, legally shaky, and largely untrusted operator base. Bartan Oren, Maurantonio Caprolu, Savio Sciancalepore, Nicola Zannone, Roberto Di Pietro |
AsiaCCS | 5 |
| 2026 | Nominated Proof of Stake: A Reality Check
Maurantonio Caprolu, Elia Onofri, Omar Eldesouky, Roberto Di Pietro |
ICBC | 4 |
| 2026 | PumpSense: Real-Time Detection and Target Extraction of Crypto Pump-and-Dumps on Telegram
Ahmed Mahrous, Roberto Di Pietro |
ICBC | 2 |
| 2026 | Toward estimating speculation in a cryptocurrency transaction network: The Polkadot case study
Maurantonio Caprolu, Roberto Di Pietro, Flavio Lombardi, Elia Onofri |
Comput. Networks | 2 |
| 2026 | OxiMoRa : Oxidation monitoring of electrochemical steel corrosion based on harmonic radar and deep learning
Nathanaël Denis, Roberto Di Pietro |
Expert Syst. Appl. | 2 |
| 2025 | NoBU: An effective and viable cyber-physical solution to thwart BadUSB attacks
Andrea Ciccotelli, Maurantonio Caprolu, Roberto Di Pietro |
AsiaCCS | 3 |
| 2025 | The Hidden Dangers of Public Serverless Repositories: An Empirical Security Assessment
Eduard Marin, Jinwoo Kim 0006, Alessio Pavoni, Mauro Conti, Roberto Di Pietro |
ESORICS (3) | 5 |
| 2025 | SoK: A Structured Analysis of Economic and Technical Stablecoin-Related Research
Ahmed Mahrous, Maurantonio Caprolu, Roberto Di Pietro |
ICBC | 3 |
| 2025 | A Spectral and Energy Efficient Transmission Scheme for OFDM-based Communication SystemsabstractThis paper introduces a new frequency domain index modulation (FD-IM) technique for a general orthogonal frequency-division multiplexing (OFDM)-based communication system. The proposed technique has been designed to enhance both the spectral and the energy efficiencies of OFDM-based communication systems. In particular, we propose a novel coding scheme for the symbols to be transmitted that leverages the absence of transmission itself to encode a symbol. To the best of our knowledge, this is the first usage of such a coding scheme in the FD-IM OFDM domain. The expected benefits of the proposed solution are as follows: (i) It enhances the spectral efficiency, by increasing the total number of transmit bits for a given set of subcarriers; and, (ii) It improves the energy efficiency. To evaluate and compare the advantages of the proposed FD-IM technique with a baseline subcarrier-index modulated (SIM)-OFDM method, we first have derived the closed-form expressions of the energy gain and the transmit bit gain for both techniques, with respect to the equivalent standard modulation. The theoretical results show a significant enhancement in terms of improving both the spectral and the energy efficiencies of a general OFDM-based communication system. Moreover, we run an extensive experimental campaign to support our findings. Results are striking. For instance, with a binary phase-shift keying (BPSK) modulation, an energy gain of 57% and a transmit bit gain of 58% are experimentally observed. These promising results pave the way to improve the different extension versions of the SIM-OFDM technique that have been presented in the literature. Finally, we also pointed out some further applications of our proposed encoding to the general field of information processing. Aymen Omri, Javier Hernandez Fernandez, Roberto Di Pietro |
Comput. Networks | 3 |
| 2025 | Drone-Mag: UAV Identification and Authentication via Electromagnetic EmissionsabstractUnmanned Aerial Vehicles (UAVs) are gaining increased popularity in a wide range of domains and applications. As a result, they are also becoming a target of malicious attacks. For example, drone impersonation of military or civilian drones can cause serious security and privacy breaches. There have been some recent contributions that aim to integrate digital certificates as an authentication tool for drones, but such software techniques are often defenseless against physical compromise. In this article, to the best of our knowledge, we are the first to propose a physical layer drone authentication framework to augment existing multifactor authentication schemes leveraging the unintentional Electromagnetic (EM) emissions of the drone’s electronic components. Our solution, Drone-Mag , exploits the inherent non-idealities and imperfections present in drones’ electronic integrated circuits that are introduced during their manufacturing process. Those emissions are hard to mimic or replicate, providing a robust basis for drone authentication. Drone-Mag is a passive, non-interactive, and privacy-preserving authentication solution and does not require software or hardware modifications to available drones. We test the performance of Drone-Mag focusing on the unintentional EM emissions of 23 drones. In particular, we addressed three main tasks: (i) identification of 14 different drones and flight controllers; (ii) authentication of 10 identical (same brand and model) drones; and (iii) rogue drone detection using autoencoders. All the listed tasks achieve a minimum average of 0.97 F1-score, showing the viability and efficiency of the proposed authentication method. Omar Adel Ibrahim, Roberto Di Pietro |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2025 | Introduction to the Special Issue on Security and Privacy of Avatar in MetaverseabstractThe Metaverse is a 3D interactive virtual community that has gained significant attention in academia, business, and industry as a potential future internet paradigm. In this space, avatars serve as key elements, acting as the primary means of human interaction. Avatars are expected to be created using real data, tailored to users' preferences, and controlled in real-time through signals from wearable devices. Avatars allow users to feel as though they are extensions of their own bodies, creating an immersive experience that blurs the line between virtual and real compared to other virtual communities. On the other hand, the avatar faces serious security and privacy problems, especially when people and the law/regulation are increasingly less tolerant of security and privacy, such as copyright, false identity detection, dataset security, authentication, and content tampering. This special issue collects 15 papers reporting the recent developments of security and privacy of avatar in metaverse. For the Avatar Copyright Protection. "A Self-Defense Copyright Protection Scheme for NFT Image Art Based on Information Embedding" addresses copyright issues related to avatars produced in the Metaverse and proposes a copyright protection scheme that not only enables tracking and verification of avatar content transactions but also validates the legality of the source and ownership of the avatar content. "Invisible Adversarial Watermarking: A Novel Security Mechanism for Enhancing Copyright Protection" addresses the potential for unauthorized access and use of image datasets used to generate avatars and proposes an image protection method that combines adversarial perturbations with invisible watermarks. This approach not only prevents illegal use of the image datasets but also enables effective tracking of data copyright. In "FaceDefend: Copyright Protection to Prevent Face Embezzle, " the authors propose a solution to the misuse problem arising from the theft of real facial image data used in avatar generation, based on defensive strategies. This approach effectively ensures copyright protection for real facial data. For the False Identity Detection for Avatars. The authors of "Audio-Visual Contrastive Pre-train for Face Forgery Detection" address the issue of potential facial privacy breaches due to the realism of avatars in virtual worlds, which can lead. Yushu Zhang 0001, William Puech, Anderson Rocha 0001, Rongxing Lu, Stefano Cresci, Roberto Di Pietro |
ACM Trans. Multim. Comput. Commun. Appl. | 6 |
| 2024 | MAG-JAM: Jamming Detection via Magnetic Emissions
Omar Adel Ibrahim, Roberto Di Pietro |
ESORICS (1) | 2 |
| 2024 | Sharing Is (S)caring: Security and Privacy Issues in Decentralized Physical Infrastructure Networks (DePIN)
Maurantonio Caprolu, Simone Raponi, Roberto Di Pietro |
NSS | 3 |
| 2024 | An efficient failure-resilient mutual exclusion algorithm for distributed systems leveraging a novel zero-message overlay structureabstractIn this paper, we provide a novel failure-resilient token-based mutual exclusion (ME) algorithm for distributed systems. Like a few other solutions in the literature, the proposed solution leverages a logical tree as its underlying topology. However, unlike any other solution, the tree is built using a probabilistic, fully distributed approach, without exchanging messages. The current tree-based ME algorithms often overlook considerations for node/link failures or offer costly methods for failure recovery. The proposed algorithm overcomes these limitations by providing an effective solution to maintain a logarithmic cost in case of node failures. The overlay structure—a unique logical tree—used to control access to the critical section maintains its consistency even when nodes fail. An extensive simulation study demonstrates the viability and efficiency of the proposed algorithm under various node failure models, and relevant metrics (e.g., node queue dimension, number of exchanged messages, and number of disconnected nodes) indicate a graceful degradation in performance with decreasing number of functioning nodes. For instance, for 4,096 nodes organized in a logical tree of arity 4 and with 4 physical nodes for logical node, a negligible number of nodes is disconnected from the tree after 250 epochs when the per-node per-epoch failure probability is pf≤0.0008. With a pf=0.0016, less than 10% of the nodes are disconnected. The proposed algorithm avoids node disconnection while minimally impacting the load of the logical tree nodes. In addition, for the same architecture, when both tree arity and cardinality are 4, after 250 epochs, the node load has demonstrated minimal variation and remains in close proximity to the original load. Moreover, experimental results also reveal a graceful degradation of algorithm performance. The fully distributed solution, rich parametrization for different trade-offs, and viability and resilience of the proposed algorithm also pave the way for future research. Mouna Rabhi, Roberto Di Pietro |
Comput. Commun. | 2 |
| 2024 | MAG-PUFs: Authenticating IoT devices via electromagnetic physical unclonable functions and deep learningabstractThe challenge of authenticating Internet of Things (IoT) devices, particularly in low-cost deployments with constrained nodes that struggle with dynamic re-keying solutions, renders these devices susceptible to various attacks. This paper introduces a robust alternative mitigation strategy based on Physical-Layer Authentication (PLA), which leverages the intrinsic physical layer characteristics of IoT devices. These unique imperfections, stemming from the manufacturing process of IoT electronic integrated circuits (ICs), are difficult to replicate or falsify and vary with each function executed by the IoT device. We propose a novel lightweight authentication scheme, MAG-PUFs, that uses the unintentional Electromagnetic (EM) emissions from IoT devices as Physical Unclonable Functions (PUFs). MAG-PUFs operate by collecting these unintentional EM emissions during the execution of pre-defined reference functions by the IoT devices. The authentication is achieved by matching these emissions with profiles recorded at the time of enrollment, using state-of-the-art Deep Learning (DL) approaches such as Neural Networks (NN) and Autoencoders. Notably, MAG-PUFs offer compelling advantages: (i) it preserves privacy, as it does not require direct access to the IoT devices; and, (ii) it provides unique flexibility, permitting the selection of numerous and varied reference functions. We rigorously evaluated MAG-PUFs using 25 Arduino devices and a diverse set of 325 reference function classes. Employing a DL framework, we achieved a minimum authentication F1-Score of 0.99. Furthermore, the scheme’s efficacy in detecting impostor EM emissions was also affirmed, achieving a minimum F1-Score of 0.99. We also compared our solution to other solutions in the literature, showing its remarkable performance. Finally, we discussed code obfuscation techniques and the impact of Radio Frequency (RF) interference on the IoT authentication process. Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro |
Comput. Secur. | 3 |
| 2024 | Audio-deepfake detection: Adversarial attacks and countermeasuresabstractAudio has always been a powerful resource for biometric authentication: thus, numerous AI-based audio authentication systems (classifiers) have been proposed. While these classifiers are effective in identifying legitimate human-generated input their security, to the best of our knowledge, has not been explored thoroughly when confronted with advanced attacks that leverage AI-generated deepfake audio. This issue presents a serious concern regarding the security of these classifiers because, e.g., samples generated using adversarial attacks might fool such classifiers, resulting in incorrect classification. In this study, we prove the point: we demonstrate that state-of-the-art audio deepfake classifiers are vulnerable to adversarial attacks. In particular, we design two adversarial attacks on a state-of-the-art audio-deepfake classifier, i.e., the Deep4SNet classification model, which achieves 98.5% accuracy in detecting fake audio samples. The designed adversarial attacks1 leverage a generative adversarial network architecture and reduce the detector’s accuracy to nearly 0%. In particular, under graybox attack scenarios, we demonstrate that when starting from random noise, we can reduce the accuracy of the state-of-the-art detector from 98.5% to only 0.08%. To mitigate the effect of adversarial attacks on audio-deepfake detectors, we propose a highly generalizable, lightweight, simple, and effective add-on defense mechanism that can be implemented in any audio-deepfake detector. Finally, we discuss promising research directions. Mouna Rabhi, Spiridon Bakiras, Roberto Di Pietro |
Expert Syst. Appl. | 3 |
| 2024 | CrowdFAB: Intelligent Crowd-Forecasting Using Blockchains and its Use in SecurityabstractCrowdsourcing applications, such as Uber for ride-sharing, enable distributed problem-solving. A subset of these applications is intelligent crowd-forecasting applications, e.g., Virustotal, for malware detection. In crowd-forecasting applications, multiple agents respond with predictions about potential future event outcome(s). These responses are then combined to assess the events collaboratively and act accordingly. Unlike conventional crowdsourcing applications that only communicate information, crowd-forecasting applications need to additionally process information to achieve a collaborative assessment. Hence, they require knowledge-based systems instead of simple storage-based ones for crowdsourcing applications. Most existing crowd-forecasting systems are centralized, leading to the inherent single point of failure and inefficient collaborative assessment. This paper presents CrowdFAB,CrowdsourcedForecastingApplications usingBlockchains. We deploy a knowledge-based blockchain paradigm that transforms blockchains from simple storage to knowledge-based systems, thereby achieving crowd-forecasting requirements without centralization. In addition, we formulate a novel reputation scheme that assigns reputations to agents based on their performance. We then use this scheme when making assessments. We implement and analyze CrowdFAB in terms of overhead and security features. Further, we evaluate CrowdFAB for a collaborative malware detection use case, where multiple detectors are involved for crowd forecasting. Results demonstrate CrowdFAB's superior accuracy and other metrics performance compared to other works with the same settings. Tara Salman, Ali Ghubaish, Roberto Di Pietro, Mohamed Baza, Hani Alshahrani, Raj Jain, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Lightweight Privacy-Preserving Proximity Discovery for Remotely-Controlled DronesabstractDiscovering mutual proximity and avoiding collisions is one of the most critical services needed by the next generation of Unmanned Aerial Vehicles (UAVs). However, currently available solutions either rely on sharing mutual locations, neglecting the location privacy of involved parties, or are applicable for fully autonomous vehicles only—leaving unaddressed Remotely-Piloted UAVs’ safety needs. Alternatively, proximity can be discovered by adding sensing capabilities. However, in addition to the cost of the sensors, the complexity of integration, and the toll on the energy budget, the effectiveness of such solutions is usually limited by short detection ranges, making them hardly useful in high-mobility scenarios. In this paper, we propose LPPD (an acronym for Lightweight Privacy-preserving Proximity Discovery), a unique solution for privacy-preserving proximity discovery among remotely piloted UAVs based on the exchange of wireless messages. LPPD integrates two main building blocks: (i) a custom space tessellation technique based on randomized spheres; and, (ii) a lightweight cryptographic primitive for private-set intersection. Another feature enjoyed by LPPD is that it does not require online third parties. LPPD is rooted in sound theoretical results and is supported by an experimental assessment performed on a real drone. In particular, experimental results show that LPPD achieves 100% proximity discovery while taking only 39.66 milliseconds in the most lightweight configuration and draining only the 5 · 10− 6% of the UAV’s battery capacity. In addition, LPPD’s security properties are formally verified. Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro |
ACSAC | 3 |
| 2023 | Understanding Polkadot Through Graph Analysis: Transaction Model, Network Properties, and Insights
Hanaa Abbas, Maurantonio Caprolu, Roberto Di Pietro |
FC | 3 |
| 2023 | LLD: A Low Latency Detection Solution to Thwart Cryptocurrency Pump & DumpsabstractPump and Dump schemes represent a threat to any market. While this issue has long been regulated in mature markets, in unregulated markets, such as crypto exchanges, this plague is very present, and even exacerbated by the low capitalizaton of many cryptocurrencies that represent the perfect target for such a fraudulent scheme. In this paper, we detail a Low Latency Detection solution (LLD) based on deep learning to automatically detect pump and dump activities on centralized cryptocurrency exchanges. We train a LSTM-based auto-encoder on BTC valuations, which can reliably be considered a proxy for regular trading-due to their larger capitalization. We use this auto-encoder to predict valuations on alt coins and use thresholding on a Gaussian tail condition to trigger detection. We argue that low latency detection is paramount for the practicality of such approaches. Unlike previous methods, our solution (LLD) detects the majority of pumps in less than five minutes (2.2 minutes on average) when using OHLCV data at one-minute resolution. In addition, we use social media data only to generate ground truths during testing. We show that in many cases a significant amount of the trade volume could have been saved had LLD been used to trigger trade suspension mechanisms. The idiosyncratic approach of our scheme, its sound rationale and viability, combined with the quality of achieved results-tested over an extensive experimental campaign-and the insights discussed in the paper also pave the way for further research in the field. Ahmad Sani Bello, Jens Schneider 0002, Roberto Di Pietro |
ICBC | 3 |
| 2023 | Account Clustering in the Polkadot Network: Heuristic, Experiments, and InsightsabstractThis paper investigates, for the first time, user account clustering in the Polkadot network, one of the most innovative account-based altcoins in the market. To achieve this goal, we levereged the “deposit address reuse” heuristic on the Polkadot relay chain. In detail, we propose a novel deposit address detection methodology, combined with a general clustering strategy. To show the viability of our approach, we present a case study involving Binance and Kraken, the two major exchanges active in the Polkadot network. The analysis extends over a sensitive time window-starting from Polkadot genesis (May 2020) up to block 12,532,600 (October 2022). Thanks to the proposed methodology, we clustered more than 145,440 accounts belonging to exchanges, and more than 25,000 user accounts, representing around 25% of all the Binance/Kraken on-chain customers. The general applicability of our technique, the preliminary achieved results-showing both the viability and the value provided by our approach-, and the research hints discussed in the paper, also pave the way for further research in the field. Maurantonio Caprolu, Roberto Di Pietro |
ICBC | 2 |
| 2023 | Characterizing the 2022- Russo-Ukrainian Conflict Through the Lenses of Aspect-Based Sentiment Analysis: Dataset, Methodology, and Key FindingsabstractOnline social networks (OSNs) play a crucial role in modern society by supporting free expression, information sharing, and social movement organization. However, they are also the tool of choice to spread disinformation, hate speech, and support propaganda. As such, it is crucial to analyze OSNs, particularly during critical events such as elections, pandemics, and conflicts, when disinformation campaigns may seek to undermine the democratic values of a nation. This paper analyzes the general-public perception of the first phases of the 2022- Russo-Ukrainian conflict on Twitter. To this end, we developed a general methodology consisting of several steps. We built a dataset of 5.5+ million tweets related to the subject, generated by 1.8+ million unique users. Then, we cluster users into five categories, and combining statistical analysis and aspect-based sentiment analysis (ABSA), we quantitatively and qualitatively investigate the spread of information during the conflict. Our analysis revealed several important insights, including anomalies in the behavior of specific user categories and their sentiment trends and a spike in the daily account creation rate before the conflict. Other than being interesting on their own, our findings also have significant implications for future research on how disinformation campaigns are executed and on developing effective strategies to mitigate their impact. Maurantonio Caprolu, Alireza Sadighian, Roberto Di Pietro |
ICCCN | 3 |
| 2023 | Performance Analysis of Physical Layer Security in Power Line Communication NetworksabstractDue to the broadcast nature of power line communication (PLC) channels, confidential information exchanged on the power grid is prone to malicious exploitation by any PLC device connected to the same power grid. To combat the ever-growing security threats, physical layer security (PLS) has been proposed as a viable safeguard or complement to existing security mechanisms. In this paper, the security analysis of a typical PLC adversary system model is investigated. In particular, we derive the expressions of the corresponding average secrecy capacity (ASC) and the secrecy outage probability (SOP) of the considered PLC system. In addition, numerical results are presented to validate the obtained analytical expressions and to assess the relevant PLS performances. The results show significant impacts of the transmission distances and the used carrier frequency on the overall transmission security. Javier Hernandez Fernandez, Aymen Omri, Roberto Di Pietro |
ISCC | 3 |
| 2023 | Subcarrier-Index Modulation for OFDM-based PLC SystemsabstractIn this paper, we investigate and evaluate the performances of a subcarrier-index modulation (SIM) technique within an orthogonal frequency division multiplexing (OFDM)-based narrow-band (NB)-power line communication (PLC) system. The SIM technique has been proposed and used mainly in wireless communications to enhance energy and spectral efficiencies. To evaluate the advantages of this technique in PLC, Monte Carlo simulations were performed using field measurements of PLC noise and channel frequency response (CFR). The results show significant advantages in terms of improving the overall system energy and spectral efficiencies, especially for single-level modulation. For instance, when using the SIM-OFDM technique, with a binary phase-shift keying (BPSK) modulation, an energy gain of 66.66% and a bit gain of 50%, with respect to the standard modulation, can be observed. Aymen Omri, Javier Hernandez Fernandez, Roberto Di Pietro |
ISCC | 3 |
| 2023 | Secure and Successful Transmission Probability Analysis for PLC NetworksabstractIn this paper, we analyze a typical PLC system's data transmission security and reliability. In particular, we consider a passive adversary model–commonly assumed in the literature–and a friendly jamming technique to thwart the attacker. Overall, several contributions are provided: First, the most relevant PLS techniques in the literature are detailed, focusing on the applications, advantages, and disadvantages of each technique, as well as the related PLS performance analysis metrics. Then, we derive the expression of a novel PLC performance analysis metric: the secure and successful transmission probability (SSTP) of the considered PLC system model. Such a metric captures aspects that are not considered in the available ones, and we use it to analyze our use case, considering the adoption of a friendly jamming technique to thwart a passive eavesdropping attack. A complete analytical characterization of the introduced use case is provided. Finally, numerical results are presented to validate the obtained analytical expressions and to assess the relevant PLS and link reliability performances. The results show the significant impacts of the transmission distances, the used carrier frequency, and the jamming signal power on the overall quality of the achieved security and transmission performances. Other than being interesting on their own, these results also provide direct guidance on effectively tuning countermeasures against the considered adversary. Aymen Omri, Javier Hernandez Fernandez, Roberto Di Pietro |
ISNCC | 3 |
| 2023 | Mag-Auth: Authenticating Wireless Transmitters and Receivers on the Receiver Side via Magnetic EmissionsabstractDevice authentication over the wireless channel is still an open issue. This is especially true for low-end devices like the IoT ones, where the overhead required by traditional asymmetric cryptographic techniques can be overwhelming, or-more in general-when the crypto material might have been compromised. A robust solution for the above scenarios is Physical-Layer Authentication (PLA), which exploits the inherent intrinsic unique features of the wireless devices to achieve low-cost, crypto-less authentication. In this paper, we present Mag-Auth, a novel and lightweight authentication scheme that leverages the Electro-Magnetic (EM) emissions released at the joint connection between the wireless device and its antenna in response to an excitation signal. Specifically, Mag-Auth trains, on the collected EM emissions, an autoencoder and a Neural Network (NN). The autoencoder is employed to reject wireless devices that do not belong to the set the autoencoder and the NN have been trained over, while the NN is applied to uniquely identify the different classes of wireless transmitter-receiver pairs. Mag-Auth enjoys some unique features: it is privacy-preserving as it does not require to have access to the radio board (unlike, for instance, in-phase/quadrature (IQ)-based PLA methods); it caters to both wireless transmitter and receiver authentication scenarios; and, it sports striking performance. Indeed, our extensive experimental campaign involving 600 combinations of various wireless devices and antennas (including SDRs and IoTs) unveiled a minimum average F1-Score of 0.94 when classifying samples collected over a maximum length of 1s, proving the effectiveness and viability of using EM emissions as a lightweight, efficient, and robust authentication mechanism. Finally, we also released the collected EM emissions raw data to foster further investigations and development by Academia, Industry, and practitioners. Omar Adel Ibrahim, Roberto Di Pietro |
WISEC | 2 |
| 2023 | Extending device noise measurement capacity for OFDM-based PLC systems: Design, implementation, and on-field validationabstractNoise measurement in power line communication (PLC) systems is a common activity performed by grid operators for network tuning operations. Usually, these measurements are carried out with portable devices that have a fixed sensing and storage capacity. In this context, this paper presents a software-only solution for enhancing the performance of noise measurements in PLC systems. In detail: (i) we extend the measurement capacity in terms of the maximum number of samples that can be detected continuously, by using a machine learning (ML)-powered low complexity algorithm; and, (ii) we reduce the discontinuity period between successive measurements. This latter feature enables the possibility of collecting more continuous data. To show the viability of our proposal, we conducted a field measurements campaign to measure the scheme’s accuracy and the measurement capacity extension ratio (MCER). The introduced approach is able to increase the MCER by up to 8 times, in the considered PLC environments, with an accuracy above 90%. While the proposed approach has a clear application—improving current devices’ noise measurements capability without requiring costly hardware upgrades—, the technique herein shown has a general applicability, and could hence pave the way for further applications in related fields. Aymen Omri, Javier Hernandez Fernandez, Roberto Di Pietro |
Comput. Networks | 3 |
| 2023 | Content privacy enforcement models in decentralized online social networks: State of play, solutions, limitations, and future directionsabstractIn recent years, Decentralized Online Social Networks (DOSNs) have been attracting the attention of many users because they reduce the risk of censorship, surveillance, and information leakage from the service provider. In contrast to the most popular Online Social Networks, which are based on centralized architectures (e.g., Facebook, Twitter, or Instagram), DOSNs are not based on a single service provider acting as a central authority. Indeed, the contents that are published on DOSNs are stored on the devices made available by their users, which cooperate to execute the tasks needed to provide the service. A specific form of cooperation is to store the content published by a user on other peers’ devices as well, hence dramatically enhancing availability. Consequently, such contents must be properly protected by the DOSN infrastructure, in order to ensure that they can be really accessed only by users who have the permission of the publishers. As a consequence, DOSNs require efficient solutions for protecting the privacy of the contents published by each user with respect to the other users of the social network. This is exactly the focus of this paper. In particular, we investigate and compare the principal content privacy enforcement models adopted by current DOSNs evaluating their suitability to support different types of privacy policies based on user groups. Such evaluation is carried out by implementing several models and comparing their performance for the typical operations performed on groups, i.e., content publish, user join, and user leave. In detail, we show that the join operation incurs a similar cost for all the privacy enforcement models and groups, while for the leave operation performance is greatly affected by the selected solution, which must be evaluated on a case-by-case basis depending on both the type and the activity level of the group—as analytically detailed in our contribution. Further, we also highlight the limitations of current approaches and show future research directions. The provided contributions, other than being interesting on their own, set a blueprint for researchers and practitioners interested in implementing DOSNs, and highlight a few open research directions. Andrea De Salve, Paolo Mori, Laura Ricci, Roberto Di Pietro |
Comput. Commun. | 4 |
| 2023 | LENTO: Unpredictable Latency-based continuous authEntication for Network inTensive IoT envirOnments
Mohammed Al-Sadi, Roberto Di Pietro, Flavio Lombardi, Matteo Signorini |
Future Gener. Comput. Syst. | 2 |
| 2023 | A2RID - Anonymous Direct Authentication and Remote Identification of Commercial DronesabstractThe recent worldwide introduction of RemoteID (RID) regulations forces all unmanned aircrafts (UAs), also known as drones, to broadcast in plaintext on the wireless channel their identity and real-time location, for accounting and monitoring purposes. Although improving drones’ monitoring and situational awareness, the RID rule also generates significant privacy concerns for UAs’ operators, threatened by the ease of tracking of UAs and related confidentiality and privacy concerns connected with the broadcasting of plaintext identity information. In this article, we propose anonymous direct authentication and remote identification ($A^{2}RID$), a protocol suite for$A^{2}RID$of heterogeneous commercial UAs.$A^{2}RID$integrates and adapts protocols for anonymous message signing to work in the UA domain, coping with the constraints of commercial drones and the tight real-time requirements imposed by the RID regulation. Overall, the protocols in the$A^{2}RID$suite allow a UA manufacturer to pick the configuration that best suits the capabilities and constraints of the drone, i.e., either a processing-intensive but memory-lightweight solution (namely,$CS-A^{2}RID$) or a computationally friendly but memory-hungry approach (namely,$DS-A^{2}RID$). Besides formally defining the protocols and formally proving their security in our setting, we also implement and test them on real heterogeneous hardware platforms, i.e., the Holybro X-500 and the ESPcopter, releasing open-source the produced code. For all the protocols, we demonstrated experimentally the capability of generating anonymous RemoteID messages well below the time bound of 1 s required by RID, while at the same time having quite a limited impact on the energy budget of the drone. Eva Wisse, Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro |
IEEE Internet Things J. | 4 |
| 2023 | SpreadMeNot: A Provably Secure and Privacy-Preserving Contact Tracing ProtocolabstractA plethora of contact tracing apps have been developed and deployed in several countries around the world in the battle against Covid-19. However, people are rightfully concerned about the security and privacy risks of such applications. To address these issues, in this paper we provide two main contributions. First, we present an in-depth analysis of the security and privacy characteristics of the most prominent contact tracing protocols, under both passive and active adversaries. The results of our study indicate that all protocols are vulnerable to a variety of attacks, mainly due to the deterministic nature of the underlying cryptographic protocols. Our second contribution is the design and implementation of SpreadMeNot, a novel contact tracing protocol that can defend against most passive and active attacks, thus providing strong (provable) security and privacy guarantees that are necessary for such a sensitive application. Our detailed analysis, both formal and experimental, shows that SpreadMeNot satisfies security, privacy, and performance requirements, hence being an ideal candidate for building a contact tracing solution that can be adopted by the majority of the general public, as well as to serve as an open-source reference for further developments in the field. Pietro Tedeschi, Spiridon Bakiras, Roberto Di Pietro |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | PPCA - Privacy-Preserving Collision Avoidance for Autonomous Unmanned Aerial VehiclesabstractCurrent collision avoidance techniques deployed on Unmanned Aerial Vehicles (UAVs) rely on short-range sensors, such as proximity sensors, cameras, and microphones. Unfortunately, their efficiency is significantly limited in several situations; for instance, when a remote UAV approaches at high velocity, or when the surrounding environment is impaired (e.g., fog, noise). In the cited cases, to avoid collisions and maintain self-separation, UAVs often rely on the indiscriminate broadcast of their location. Therefore, an adversary could easily identify the location of the UAV and attack it, e.g., by physically shutting it down, launching wireless jamming attacks, or continuing tracking its movements. To address the above-introduced threats, in this article we present PPCA, a lightweight, distributed, and privacy-preserving scheme to avoid collisions among UAVs. Our solution, based on an ingenious tessellation of the space, is accompanied by a thorough analytical model and is supported by an extensive experimental campaign performed on a real 3DR-Solo drone. The achieved results are striking: PPCA can efficiently and effectively avoid collisions among UAVs, by requiring a limited bandwidth and computational overhead (84.85% less than traditional privacy-preserving proximity testing approaches), while providing unique benefits in terms of privacy of the participating UAVs. Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | PAST-AI: Physical-Layer Authentication of Satellite Transmitters via Deep LearningabstractPhysical-layer security is regaining traction in the research community, due to the performance boost introduced by deep learning classification algorithms. This is particularly true for sender authentication in wireless communications via radio fingerprinting. However, previous research mainly focused on terrestrial wireless devices while, to the best of our knowledge, none of the previous work considered satellite transmitters. The satellite scenario is generally challenging because, among others, satellite radio transducers feature non-standard electronics (usually aged and specifically designed for harsh conditions). Moreover, the fingerprinting task is specifically difficult for Low-Earth Orbit (LEO) satellites (like the ones we focus in this paper) since they feature a low bit-rate and orbit at about 800 Km from the Earth, at a speed of around 25,000 Km/h, thus making the receiver experiencing a down-link with unique attenuation and fading characteristics. In this paper, we investigate the effectiveness and main limitations of AI-based solutions to the physical-layer authentication of LEO satellites. Our study is performed on massive real data—more than$100M$I-Q samples—collected from an extensive measurements campaign on the IRIDIUM LEO satellites constellation, lasting 589 hours. Our results show that Convolutional Neural Networks (CNN) and autoencoders (if properly calibrated) can be successfully adopted to authenticate the satellite transducers, with an accuracy spanning between 0.8 and 1, depending on prior assumptions. However, the relatively high number of I-Q samples required by the proposed methodology, coupled with the low bandwidth of satellite link, might prevent the detection of the spoofing attack under certain configuration parameters. Gabriele Oligeri, Savio Sciancalepore, Simone Raponi, Roberto Di Pietro |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | FN2: Fake News DetectioN Based on Textual and Contextual Features
Mouna Rabhi, Spiridon Bakiras, Roberto Di Pietro |
ICICS | 3 |
| 2022 | FRACTAL: Single-Channel Multi-factor Transaction Authentication Through a Compromised Terminal
Savio Sciancalepore, Simone Raponi, Daniele Caldarola, Roberto Di Pietro |
ICICS | 4 |
| 2022 | Securing Content in Decentralized Online Social Networks: Solutions, Limitations, and the Road AheadabstractThe most popular On-line Social Networks (OSNs) are based on centralized architectures where service providers (e.g., Facebook, Twitter, or Instagram) have full control over the data published by their user---a requirement of their business model, based on the monetization of the cited data [2]. In addition, such centralized architectures also increase the risk of censorship, surveillance, and information leakage [3]. Distributed On-line Social Networks (DOSNs), instead, are typically based on a P2P architecture, where there is no central service provider in control of user data. Indeed, the contents that are published on DOSNs are stored on user-provided devices, that also cooperate to execute the tasks needed to realize the intended service. Most of the popular DOSNs, in an effort to help users smoothly regulate content sharing in adherence to their privacy preferences, allow to organize users in groups. In this way, each user can choose to share content with the users belonging to specific groups only. The lack of a (logically) centralized, third party managed, reliable infrastructure to guarantee content availability---whether a given user is on-line or not---has led to have the contents published by a user to be stored on the devices of other users as well. Indeed, such a choice increases the chances that at least one of the cooperating users device (and the contents stored therein) is online when the content is required. Given the two above introduced (conflicting) requirements: group-oriented privacy setting and distributed storage, a critical feature of DOSNs is that published contents must be properly protected by the DOSN infrastructure, in order to ensure that they can be accessed only by users that have the appropriate permissions---granted by the publishers. Hence, DOSNs require efficient solutions for protecting the privacy of the contents published by each user with respect to the other users of the social network. While some preliminary solutions have been proposed [1], the literature lacks of a general systematization of DOSNs, in particular for what concerns the access control models in place to secure access and to ensure content availability. The same lack of systematization can be noticed when considering the pros and cons of the different models in place, especially when analyzed through the lenses of performance. Roberto Di Pietro |
SACMAT | 1 |
| 2022 | MAG-PUF: Magnetic Physical Unclonable Functions for Device Authentication in the IoT
Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro |
SecureComm | 3 |
| 2022 | MAG-PUF - Authenticating IoT Devices via Magnetic Physical Unclonable FunctionsabstractAuthenticating Internet of Things (IoT) devices is still a defiant task, despite the remarkable technological advancement achieved in the last few years. The issue is especially challenging in scenarios involving low-cost constrained nodes, hardly supporting dynamic re-keying algorithms. To provide a viable general-purpose solution, we propose MAG-PUF: a novel and lightweight authentication scheme using unintentional magnetic emissions produced by IoT devices to implement Physical Unclonable Functions (PUFs). Our extensive experimental campaign, involving 25 Arduino boards and four example reference functions, unveiled an outstanding authentication accuracy of over 99%, proving the feasibility of using code-driven magnetic emissions as a lightweight, efficient, and robust PUF for IoT deployments. Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro |
WISEC | 3 |
| 2022 | GPS spoofing detection via crowd-sourced information for connected vehiclesabstractModern vehicular systems rely on the Global Positioning System (GPS) technology to provide accurate and timely services. However, the GPS has been proved to be characterized by an intrinsic insecure design, thus being subject to several security attacks. Current solutions can reliably detect GPS spoofing attacks leveraging the physical features of the received GPS signals or resorting to multiple antennas. However, these techniques cannot be deployed when the physical properties of the received signals cannot be accessed, which is the most general case for commercial GPS receivers. Alternative solutions in the literature rely on the cross-check of the received signal with information coming from additional sources. However, such proposals are typically limited to a single source, are rarely supported by experimental results, and do not provide insights on the impact of several parameters, such as detection accuracy, time, false-positives, and robustness to malicious information. To overcome the cited limitations, in this paper, we propose an innovative approach, resorting to combined crowd-sourced information from the mobile cellular infrastructure and the WiFi networks to detect GPS spoofing attacks. Our analysis leverages an extensive experimental dataset, available online for the research community, gathered by driving around a car in urban, suburban, and rural scenarios, for around 5 h and covering more than 196 km. Our solution allows for a tunable tradeoff between detection delay and false positive; for instance, we can detect an attack in approximately 6 s, when leveraging the information coming from only the WiFi, while the delay increases to 30 s when using the information from the mobile cellular network, still achieving a false positive probability strictly less than 0.01. We also show the limitations and trade-offs of our approach, in terms of minimum detection accuracy, time, and robustness to malicious information. The data adopted in this work are publicly released to allow results replicability and foster further research in the highlighted directions. Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro |
Comput. Networks | 4 |
| 2022 | Satellite-based communications security: A survey of threats, solutions, and research challengesabstractSatellite-based Communication (SATCOM) systems are gaining renewed momentum in Industry and Academia, thanks to innovative services introduced by leading tech companies and the promising impact they can deliver towards the global connectivity objective tackled by early 6G initiatives. On the one hand, the emergence of new manufacturing processes and radio technologies promises to reduce service costs while guaranteeing outstanding communication latency, available bandwidth, flexibility, and coverage range. On the other hand, cybersecurity techniques and solutions applied in SATCOM links should be updated to reflect the substantial advancements in attacker capabilities characterizing the last two decades. However, business urgency and opportunities are leading operators towards challenging system trade-offs, resulting in an increased attack surface and a general relaxation of the available security services. In this paper, we tackle the cited problems and present a comprehensive survey on the link-layer security threats, solutions, and challenges faced when deploying and operating SATCOM systems. Specifically, we classify the literature on security for SATCOM systems into two main branches, i.e., physical-layer security and cryptography schemes. Then, we further identify specific research domains for each of the identified branches, focusing on dedicated security issues, including, e.g., physical-layer confidentiality, anti-jamming schemes, anti-spoofing strategies, and quantum-based key distribution schemes. For each of the above domains, we highlight the most essential techniques, peculiarities, advantages, disadvantages, lessons learned, and future directions. Finally, we also identify emerging research topics whose additional investigation by Academia and Industry could further attract researchers and investors, ultimately unleashing the full potential behind ubiquitous satellite communications. Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro |
Comput. Networks | 3 |
| 2022 | Noise2Weight: On detecting payload weight from drones acoustic emissionsabstractThe increasing popularity of autonomous and remotely-piloted drones has paved the way for several use-cases and application scenarios, including merchandise delivery, surveillance, and warfare, to cite a few. In many application scenarios, estimating with zero-touch the weight of the payload carried by a drone before it approaches could be of particular interest, e.g., to provide early tampering detection when the weight of the payload is sensitively different from the expected one. To the best of our knowledge, we are the first to investigate the possibility to remotely detect the weight of the payload carried by a commercial drone by analyzing its acoustic fingerprint. Rooted on a sound methodology and validated by an extensive experimental on-field campaign carried out on a reference 3DR Solo drone, we characterize how the differences in the thrust needed by a drone to carry different payloads affect the speed of the motors and the blades and, in turn, introduces significant variations in the resulting acoustic fingerprint. We applied the above findings to different use-cases and scenarios, characterized by different computational capabilities of the detection system. Results are striking: using the Mel-Frequency Cepstral Coefficients (MFCC) components of the audio signal and different Support Vector Machine (SVM) classifiers, we showed that it is possible to achieve a minimum classification accuracy of 98% in the detection of the specific payload class carried by the drone, using an acquisition time of only 0.25 s—performances improve when using longer time acquisitions. All the data used for our analysis have been released as open-source, to enable the community to validate our findings and use such data as a ready-to-use basis for further investigations. Omar Adel Ibrahim, Savio Sciancalepore, Roberto Di Pietro |
Future Gener. Comput. Syst. | 3 |
| 2022 | COVID-19 and cybersecurityabstractThe COVID19 pandemic is having a worldwide impact on the way business is conducted, people interact, work is organised, and more. In a line, it is changing our way of life. In this Special Issue: COVID-19 and Cybersecurity, we focus on the many ramifications of COVID-19 into the Cybersecurity realm. Other Information Published in: IET Information Security License: http://creativecommons.org/licenses/by-nc/4.0/ See article on publisher's website: https://dx.doi.org/10.1049/ise2.12084 Roberto Di Pietro, Ni Trieu, Vincenzo Iovino |
IET Inf. Secur. | 1 |
| 2022 | Auth-AIS: Secure, Flexible, and Backward-Compatible Authentication of Vessels AIS BroadcastsabstractAutomatic Identification System (AIS) is the de-facto communication standard used by vessels to broadcast identification and position information. However, being AIS communications neither encrypted nor authenticated, they can be eavesdropped and spoofed by adversaries, leading to potentially threatening scenarios. Existing solutions, including the ones conceived in the avionics domain, do not consider integration with the AIS standard, and they do not provide protection against rogue messages flooding. In this article, we propose Auth-AIS, a secure, flexible, standard-compliant, and backward-compatible authentication framework to secure AIS broadcast messages. Auth-AIS leverages existing sound cryptographic tools, including TESLA and Bloom Filters, inheriting their security properties while contextualizing them in the AIS technology. Auth-AIS is a software-only solution, that can be seamlessly integrated into existing AIS deployments, without requiring any hardware replacement. Its innovative design also provides backward-compatibility—i.e., Auth-AIS messages can be received also by AIS users not adopting Auth-AIS, while renouncing at its security guarantees. Auth-AIS can work in either two configuration modes: Deterministic Security Configuration, able to achieve low-delay authentication with a message overhead of 75 percent, or Probabilistic Security Configuration, reducing the message overhead down to 35.71 percent, while experiencing a marginal increase in the authentication delay. All these security configurations guarantee an 80 bits equivalent security level and false-positive rate less than 2--40. Note that these latter security parameters can easily be tuned to fit different security requirements. Finally, the source code of Auth-AIS in the GNURadio ecosystem has been released as open-source, to foster research activities from both Industry and Academia on secure AIS communications. Savio Sciancalepore, Pietro Tedeschi, Ahmed Aziz, Roberto Di Pietro |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Fake News Propagation: A Review of Epidemic Models, Datasets, and InsightsabstractFake news propagation is a complex phenomenon influenced by a multitude of factors whose identification and impact assessment is challenging. Although many models have been proposed in the literature, the one capturing all the properties of a real fake-news propagation phenomenon is inevitably still missing. Modern propagation models, mainly inspired by old epidemiological models, attempt to approximate the fake-news propagation phenomena by blending psychological factors, social relations, and user behavior. This work provides an in-depth analysis of the current state of fake-news propagation models supported by real-world datasets. We highlighted similarities and differences in the modeling approaches, wrapping up the main research trends. Propagation models, transitions, network topologies, and performance metrics have been identified and discussed in detail. The thorough analysis we provided in this article, coupled with the highlighted research hints, have a high potential to pave the way for future research in the area. Simone Raponi, Zeinab Khalifa, Gabriele Oligeri, Roberto Di Pietro |
ACM Trans. Web | 4 |
| 2021 | ARID: Anonymous Remote IDentification of Unmanned Aerial VehiclesabstractTo enable enhanced accountability of Unmanned Aerial Vehicles (UAVs) operations, the US-based Federal Avionics Administration (FAA) recently published a new dedicated regulation, namely RemoteID, requiring UAV operators to broadcast messages reporting their identity and location. The enforcement of such a rule, mandatory by 2022, generated significant concerns on UAV operators, primarily because of privacy issues derived by the indiscriminate broadcast of the plain-text identity of the UAV on the wireless channel. Pietro Tedeschi, Savio Sciancalepore, Roberto Di Pietro |
ACSAC | 3 |
| 2021 | Cryptomining makes noise: Detecting cryptojacking via Machine LearningabstractCryptojacking occurs when an adversary illicitly runs crypto-mining software over the devices of unaware users. This novel cybersecurity attack, that is emerging in both the literature and in the wild, has proved to be very effective given the simplicity of running a crypto-client into a target device. Several countermeasures have recently been proposed, with different features and performance, but all characterized by a host-based architecture. The cited solutions, designed to protect the individual user, are not suitable for efficiently protecting a corporate network, especially against insiders. In this paper, we propose a network-based approach to detect and identify crypto-clients activities by solely relying on the network traffic, even when encrypted and mixed with non-malicious traces. First, we provide a detailed analysis of the real network traces generated by three major cryptocurrencies, Bitcoin, Monero, and Bytecoin, considering both the normal traffic and the one shaped by a VPN. Then, we propose Crypto-Aegis, a Machine Learning (ML) based framework built over the results of our investigation, aimed at detecting cryptocurrencies related activities, e.g., pool mining, solo mining, and active full nodes. Our solution achieves a striking 0.96 of F1-score and 0.99 of AUC for the ROC, while enjoying a few other properties, such as device and infrastructure independence. Given the extent and novelty of the addressed threat we believe that our approach, supported by its excellent results, pave the way for further research in this area. Maurantonio Caprolu, Simone Raponi, Gabriele Oligeri, Roberto Di Pietro |
Comput. Commun. | 4 |
| 2021 | DoS and DDoS attacks in Software Defined Networks: A survey of existing solutions and research challengesabstractSoftware Defined Networking (SDN) is a new networking paradigm where forwarding hardware is decoupled from control decisions. It promises to dramatically simplify network management and enable innovation and evolution. In SDN, network intelligence is logically centralized in software-based controllers (the control plane), while network devices (OpenFlow Switches) become simple packet-forwarding devices (the data plane) that can be programmed via an open interface (OpenFlow protocol). Such decoupling of the control plane from the data plane introduces various challenges that include security, reliability, load balancing, and traffic engineering. Dreadful security challenges in SDNs are denial of service (DoS) and distributed denial of service (DDoS) attacks. For instance, in SDNs, DoS/DDoS attacks could flood the control plane, the data plane, or the communication channel. Attacking the control plane could result in failure of the entire network, while attacking the data plane or the communication channel results in packet drop and network unavailability. In this paper we deliver several contributions that shed light on the field of DoS/DDoS attacks in SDNs, providing a complete background about the area, including attacks and analysis of the existing solutions. In particular, our contributions can be summarized as follow: we review and systematize the state-of-the-art solutions that address both DoS and DDoS attacks in SDNs through the lenses of intrinsic and extrinsic approaches. Moreover, the discussed countermeasures are organized accordingly to their focus, be it on detection, mitigation, prevention, or graceful degradation. Further, we survey the different approaches and tools adopted to implement the revised solutions. Finally, we also highlight possible future research directions to address DoS/DDoS attacks in SDNs. Lubna Fayez Eliyan, Roberto Di Pietro |
Future Gener. Comput. Syst. | 2 |
| 2021 | PPRQ: Privacy-Preserving MAX/MIN Range Queries in IoT NetworksabstractRange queries are widely used in several Internet-of-Things (IoT) applications as a general strategy to improve the efficiency of the system. However, the communication patterns generated by the IoT nodes could lead to the identification of the devices satisfying the query, as well as to the disclosure of the queried data. State-of-the-art solutions to address the cited security issues rely on dedicated edge/fog nodes, whose deployment could be too expensive or challenging, especially in unattended scenarios where the installation of ad hoc locations could be difficult and mains-supply is hardly available. In this article, we propose PPRQ, a resilient, scalable, and lightweight protocol that allows privacy-preserving range queries in IoT networks. PPRQ is a probabilistic scheme that can be easily adapted to MIN, MAX, and MAX/MIN range queries, while requiring only hashing and bitwise xor operations. We show that PPRQ is robust, as it can be configured to provide over 99.9% accuracy in the query results. We also prove its resiliency against passive and active adversaries for a number of interesting and realistic scenarios. Our results are rooted in sound probability theory and supported by an extensive simulation campaign, while comparisons against state-of-the-art solutions show the flexibility and adaptability of PPRQ, especially for remote and unattended scenarios. Finally, further research directions opened up by the proposed solution are also highlighted. Savio Sciancalepore, Roberto Di Pietro |
IEEE Internet Things J. | 2 |
| 2021 | Receivers location privacy in avionic crowdsourced networks: Issues and countermeasuresabstractThe lack of message encryption characterizing wireless avionic protocols, including Automatic Dependent Surveillance - Broadcast (ADS-B), recently favored the rise of a few communities that, gathering data collected by receivers at the ground or in space, offer advanced services, while at the same time releasing the cited data to the public. In this context, hiding the location of an ADS-B receiver could be useful for several reasons, including military and privacy aspects. Therefore, taking into account these considerations, the data provided by a few antennas in one of the most popular crowdsourcing platforms, Opensky Network, are released removing any information that could lead to their direct location identification. In this manuscript, we investigate the effectiveness of protecting location privacy in avionic crowdsourced networks. As a worst-case scenario, we demonstrate that, when a feasible number of receivers are deployed in the same area of a protected one, due to the nature of involved ADS-B data, standard time-based localization schemes can identify the location of any protected receiver. Our model, applied to real data, can identify the location of a protected receiver with an error ranging from 0.9 km to 2.6 km, depending on the target sensor—while the location uncertainty induced by the anonymization technique was expected to be of approximately 450 km. Our findings, supported by an extensive experimental campaign run over real data, apply to a variety of potentially protected receivers. Moreover, we also provide effective countermeasures to increase receivers’ location privacy. Finally, we discuss the trade-offs implied by the cited countermeasures, showing that it is possible to increase location privacy while not decreasing data utility. Savio Sciancalepore, Saeif Alhazbi, Roberto Di Pietro |
J. Netw. Comput. Appl. | 3 |
| 2021 | SOS: Standard-Compliant and Packet Loss Tolerant Security Framework for ADS-B CommunicationsabstractThe Automatic Dependent Surveillance - Broadcast (ADS-B) technology, already deployed by the major avionics companies (e.g., QatarAirways and AmericanAirlines), will become mandatory on board of civil and military aircraft flying in Class A, B, and C airspaces by 2020, enabling direct airplanes communications and enhanced flights monitoring. However, ADS-B has been designed without security considerations, thus being vulnerable to a variety of attacks, including message injection and messages order manipulation attacks, that can be easily performed via widely available commercial Software Defined Radios. To address these threats, we present Securing Open Skies (SOS), a standard-compliant, backward-compatible, loss-tolerant, and bandwidth efficient security framework to secure ADS-B communications. SOS leverages the real deployment of densely distributed, participatory ADS-B sensor networks such as OpenSky Network and Flight Radar, and provides message authentication and integrity security services on a time-slot basis, without resorting to any public key cryptography mechanism. Experimental performances obtained through a realistic proof-of-concept, deployed using commercial Ettus Research X310 Software Defined Radios, demonstrate the viability and effectiveness of our solution, even in presence of uniformly at random or burst packet loss events characterizing the ADS-B frequency band. For instance, SOS allows the verification of the authenticity of ADS-B messages requiring less than 50 percent of bandwidth overhead, with a percentage of verifiable slots above 80 percent, even in an highly lossy environment, characterized by a single packet loss probability of 60 percent-the process requiring less than one second: almost one tenth of similar approaches published in the literature. Finally, a thorough comparison against state of the art solutions in the literature highlights the unique security and reliability features enjoyed by SOS, as well as its practical viability. Savio Sciancalepore, Roberto Di Pietro |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | MAGNETO: Fingerprinting USB Flash Drives via Unintentional Magnetic EmissionsabstractUniversal Serial Bus (USB) Flash Drives are nowadays one of the most convenient and diffused means to transfer files, especially when no Internet connection is available. However, USB flash drives are also one of the most common attack vectors used to gain unauthorized access to host devices. For instance, it is possible to replace a USB drive so that when the USB key is connected, it would install passwords stealing tools, root-kit software, and other disrupting malware. In such a way, an attacker can steal sensitive information via the USB-connected devices, as well as inject any kind of malicious software into the host. To thwart the above-cited raising threats, we propose MAGNETO, an efficient, non-interactive, and privacy-preserving framework to verify the authenticity of a USB flash drive, rooted in the analysis of its unintentional magnetic emissions. We show that the magnetic emissions radiated during boot operations on a specific host are unique for each device, and sufficient to uniquely fingerprint both the brand and the model of the USB flash drive, or the specific USB device, depending on the used equipment. Our investigation on 59 different USB flash drives—belonging to 17 brands, including the top brands purchased on Amazon in mid-2019—reveals a minimum classification accuracy of 98.2% in the identification of both brand and model, accompanied by a negligible time and computational overhead. MAGNETO can also identify the specific USB Flash drive, with a minimum classification accuracy of 91.2%. Overall, MAGNETO proves that unintentional magnetic emissions can be considered as a viable and reliable means to fingerprint read-only USB flash drives. Finally, future research directions in this domain are also discussed. Omar Adel Ibrahim, Savio Sciancalepore, Gabriele Oligeri, Roberto Di Pietro |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2021 | Predicting Influential Users in Online Social Network GroupsabstractThe widespread adoption of Online Social Networks (OSNs), the ever-increasing amount of information produced by their users, and the corresponding capacity to influence markets, politics, and society, have led both industrial and academic researchers to focus on how such systems could be influenced . While previous work has mainly focused on measuring current influential users, contents, or pages on the overall OSNs, the problem of predicting influencers in OSNs has remained relatively unexplored from a research perspective. Indeed, one of the main characteristics of OSNs is the ability of users to create different groups types, as well as to join groups defined by other users, in order to share information and opinions. In this article, we formulate the Influencers Prediction problem in the context of groups created in OSNs, and we define a general framework and an effective methodology to predict which users will be able to influence the behavior of the other ones in a future time period, based on historical interactions that occurred within the group. Our contribution, while rooted in solid rationale and established analytical tools, is also supported by an extensive experimental campaign. We investigate the accuracy of the predictions collecting data concerning the interactions among about 800,000 users from 18 Facebook groups belonging to different categories (i.e., News, Education, Sport, Entertainment, and Work). The achieved results show the quality and viability of our approach. For instance, we are able to predict, on average, for each group, around a third of what an ex-post analysis will show being the 10 most influential members of that group. While our contribution is interesting on its own and—to the best of our knowledge—unique, it is worth noticing that it also paves the way for further research in this field. Andrea De Salve, Paolo Mori, Barbara Guidi, Laura Ricci, Roberto Di Pietro |
ACM Trans. Knowl. Discov. Data | 5 |
| 2020 | New Dimensions of Information Warfare: The Economic Pillar - Fintech and Cryptocurrencies
Maurantonio Caprolu, Stefano Cresci, Simone Raponi, Roberto Di Pietro |
CRiSIS | 4 |
| 2020 | A Survey on Computational Propaganda DetectionabstractPropaganda campaigns aim at influencing people's mindset with the purpose of advancing a specific agenda. They exploit the anonymity of the Internet, the micro-profiling ability of social networks, and the ease of automatically creating and managing coordinated networks of accounts, to reach millions of social network users with persuasive messages, specifically targeted to topics each individual user is sensitive to, and ultimately influencing the outcome on a targeted issue. In this survey, we review the state of the art on computational propaganda detection from the perspective of Natural Language Processing and Network Analysis, arguing about the need for combined efforts between these communities. We further discuss current challenges and future research directions. Giovanni Da San Martino, Stefano Cresci, Alberto Barrón-Cedeño, Seunghak Yu, Roberto Di Pietro, Preslav Nakov |
IJCAI | 5 |
| 2020 | GNSS spoofing detection via opportunistic IRIDIUM signalsabstractIn this paper, we study the privately-own IRIDIUM satellite constellation, to provide a location service that is independent of the GNSS. In particular, we apply our findings to propose a new GNSS spoofing detection solution, exploiting unencrypted IRIDIUM Ring Alert (IRA) messages that are broadcast by IRIDIUM satellites. Gabriele Oligeri, Savio Sciancalepore, Roberto Di Pietro |
WISEC | 3 |
| 2020 | BrokenStrokes: on the (in)security of wireless keyboardsabstractWireless devices resorting to event-triggered communications have been proved to suffer critical privacy issues, due to the intrinsic leakage associated with radio-frequency (RF) emissions. Gabriele Oligeri, Savio Sciancalepore, Simone Raponi, Roberto Di Pietro |
WISEC | 4 |
| 2020 | PiNcH: An effective, efficient, and robust solution to drone detection via network traffic analysis
Savio Sciancalepore, Omar Adel Ibrahim, Gabriele Oligeri, Roberto Di Pietro |
Comput. Networks | 4 |
| 2020 | Emergent properties, models, and laws of behavioral similarities within groups of twitter users
Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
Comput. Commun. | 2 |
| 2020 | LiKe: Lightweight Certificateless Key Agreement for Secure IoT CommunicationsabstractCertificateless public-key cryptography (CL-PKC) schemes are particularly robust against the leakage of secret information stored on a trusted third party (TTP). These security features are particularly relevant for Internet of Things (IoT) domains, where the devices are typically preconfigured with secret keys, usually stored locally on the TTP for following maintenance tasks. Despite some contributions already proposed for the adoption of CL-PKC schemes in constrained IoT devices, current solutions generally require high message overhead, are computationally demanding, and place a high toll on the energy budget. To close this gap, we propose LiKe, a lightweight pairing-free certificateless key agreement protocol suitable for integration in the latest ZigBee 3.0 protocol stack and constrained IoT devices. LiKe is an authenticated key agreement protocol characterized by: 1) ephemeral cryptographic materials; 2) support for intermittent connectivity with the TTP; 3) lightweight rekeying operations; and 4) robustness against impersonation attacks, even when information stored on the TTP is leaked. LiKe has been thoroughly described, and its security properties have been proved via formal tools. Moreover, we have implemented and tested it on real IoT devices, in networks with up to 11 nodes-the source code has been released as an open source. Results are striking: on the OpenMote-b hardware platform, LiKe requires a total time of 3.259 s to establish session keys on each participating device, and at most 0.258% of the overall battery capacity, emerging as a lightweight and energy-friendly solution. Finally, comparisons with competing solutions do show the superior quality and viability of our proposal. Pietro Tedeschi, Savio Sciancalepore, Areej Eliyan, Roberto Di Pietro |
IEEE Internet Things J. | 4 |
| 2020 | A Logical Key Hierarchy Based Approach to Preserve Content Privacy in Decentralized Online Social NetworksabstractDistributed Online Social Networks (DOSNs) have been proposed to shift the control over user data from a unique entity, the online social network provider, to the users of the DOSN themselves. In this paper we focus on the problem of preserving the privacy of the contents shared to large groups of users. In general, content privacy is enforced by encrypting the content, having only authorized parties being able to decrypt it. When efficiency has to be taken into account, new solutions have to be devised that: i) minimize the re-encryption of the contents published in a group when the composition of the group changes; and, ii) enable a fast distribution of the cryptographic keys to all the members ($n$) of a group, each time a set of users is removed from or added to the group by the group owner. Current solutions fall short in meeting the above criteria, while our approach requires only $O(d cdot log_d(n))$ encryption operations when a user is removed from a group (where $d$ is an input parameter of the system), and $O(2cdot log_d(n))$ when a user joins the group. The effectiveness of our approach is evaluated through simulations based on a real online social network. Andrea De Salve, Roberto Di Pietro, Paolo Mori, Laura Ricci |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Semantically-Aware Statistical Metrics via Weighting KernelsabstractDistance metrics between statistical distributions are widely used as an efficient mean to aggregate/simplify the underlying probabilities, thus enabling high-level analyses. In this paper we investigate the collisions that can arise with such metrics, and a mitigation technique rooted on kernels. In detail, we first show that the existence of colliding functions (so-called iso-curves) is widespread across metrics and families of functions (e.g., gaussians, heavy-tailed). Later, we propose a solution based on kernels for augmenting distance metrics and summary statistics, thus avoiding collisions and highlighting semantically-relevant phenomena. This study is supported by a thorough theoretical evaluation of our solution against a large number of functions and metrics, complemented by a real-world evaluation carried out by applying our solution to an existing problem. Some further research venues are also discussed. The theoretical construction and the achieved results show the soundness, viability, and quality of our proposal that, other being interesting on its own, also paves the way for further research in the highlighted directions. Stefano Cresci, Roberto Di Pietro, Maurizio Tesconi |
DSAA | 2 |
| 2019 | Next Generation Information Warfare: Challenges and Research Directions
Roberto Di Pietro |
ICISSP | 1 |
| 2019 | Location Privacy Issues in the OpenSky Network Crowdsourcing Platform
Savio Sciancalepore, Saeif Alhazbi, Roberto Di Pietro |
SecureComm (1) | 3 |
| 2019 | Drive me not: GPS spoofing detection via cellular network: (architectures, models, and experiments)abstractThe Global Positioning System (GPS) has been proved to be exposed to several cybersecurity attacks, due to its intrinsic insecure design. GPS spoofing is one of the most easiest, cheap, and dreadful attacks that can be delivered: fake GPS signals can be sent to a target device and make it moving according to a pre-computed path. Gabriele Oligeri, Savio Sciancalepore, Omar Adel Ibrahim, Roberto Di Pietro |
WiSec | 4 |
| 2019 | EXCHANge: Securing IoT via channel anonymity
Savio Sciancalepore, Gabriele Oligeri, Giuseppe Piro, Gennaro Boggia, Roberto Di Pietro |
Comput. Commun. | 5 |
| 2019 | FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDNabstractThe Software Defined Networking (SDN) paradigm decouples the logic module from the forwarding module on traditional network devices, bringing a wave of innovation to computer networks. Firewalls, as well as other security appliances, can largely benefit from this novel paradigm. Firewalls can be easily implemented by using the default OpenFlow rules, but the logic must reside in the control plane due to the dynamic nature of their rules that cannot be handled by data plane devices. This leads to a nonnegligible overhead in the communication channel between layers, as well as introducing an additional computational load on the control plane. To address the above limitations, we propose the architectural design of FORTRESS: a stateful firewall for SDN networks that leverages the stateful data plane architecture to move the logic of the firewall from the control plane to the data plane. FORTRESS can be implemented according to two different architectural designs: Stand-Alone and Cooperative, each one with its own peculiar advantages. We compare FORTRESS against FlowTracker, the state-of-the-art solution for SDN firewalling, and show how our solution outperforms the competitor in terms of the number of packets exchanged between the control plane and the data plane—we require 0 packets for the Stand-Alone architecture and just 4 for the Cooperative one. Moreover, we discuss how the adaptability, elegant and modular design, and portability of FORTRESS contribute to make it the ideal candidate for SDN firewalling. Finally, we also provide further research directions. Maurantonio Caprolu, Simone Raponi, Roberto Di Pietro |
Secur. Commun. Networks | 3 |
| 2018 | A blockchain-based Trust System for the Internet of ThingsabstractOne of the biggest challenges for the Internet of Things (IoT) is to bridge the currently fragmented trust domains. The traditional PKI model relies on a common root of trust and does not fit well with the heterogeneous IoT ecosystem where constrained devices belong to independent administrative domains. In this work we describe a distributed trust model for the IoT that leverages the existing trust domains and bridges them to create end-to-end trust between IoT devices without relying on any common root of trust. Furthermore we define a new cryptographic primitive, denoted as obligation chain designed as a credit-based Blockchain with a built-in reputation mechanism. Its innovative design enables a wide range of use cases and business models that are simply not possible with current Blockchain-based solutions while not experiencing traditional blockchain delays. We provide a security analysis for both the obligation chain and the overall architecture and provide experimental tests that show its viability and quality. Roberto Di Pietro, Xavier Salleras, Matteo Signorini, Erez Waisbard |
SACMAT | 1 |
| 2018 | ADvISE: Anomaly Detection tool for blockchaIn SystEmsabstractAnomaly detection tools play a role of paramount importance in protecting networks and systems from unforeseen attacks, usually by automatically recognizing and filtering out anomalous activities. In this paper we present ADvISE: the first Anomaly Detection tool for blockchaIn SystEms which leverages blockchain meta-data, named forks, in order to collect potentially malicious requests in the network/system while being resilient to eclipse attacks. ADvISE collects and analyzes malicious forks to build a threat database that enables detection and prevention of future attacks. Matteo Signorini, Wael Kanoun, Roberto Di Pietro |
SERVICES | 3 |
| 2018 | Docker ecosystem - Vulnerability Analysis
Antony Martin, Simone Raponi, Théo Combe, Roberto Di Pietro |
Comput. Commun. | 4 |
| 2018 | GopJam: Key-less jamming mitigation via gossiping
Roberto Di Pietro, Gabriele Oligeri |
J. Netw. Comput. Appl. | 1 |
| 2018 | Social Fingerprinting: Detection of Spambot Groups Through DNA-Inspired Behavioral ModelingabstractSpambot detection in online social networks is a long-lasting challenge involving the study and design of detection techniques capable of efficiently identifying ever-evolving spammers. Recently, a new wave ofsocial spambotshas emerged, with advanced human-like characteristics that allow them to go undetected even by current state-of-the-art algorithms. In this paper, we show that efficient spambots detection can be achieved via an in-depth analysis of their collective behaviors exploiting thedigital DNAtechnique for modeling the behaviors of social network users. Inspired by its biological counterpart, in the digital DNA representation the behavioral lifetime of a digital account is encoded in a sequence of characters. Then, we define a similarity measure for such digital DNA sequences. We build upon digital DNA and the similarity between groups of users to characterize both genuine accounts and spambots. Leveraging such a characterization, we design theSocial Fingerprintingtechnique, which is able to discriminate among spambots and genuine accounts in both a supervised and an unsupervised fashion. We also evaluate the effectiveness of Social Fingerprinting and we compare it with three state-of-the-art detection showing the superiority of our solution. Finally, among the peculiarities of our approach is the possibility to apply off-the-shelf DNA analysis techniques to study online users behaviors and to efficiently rely on a limited number of lightweight account characteristics. Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | Exploiting Digital DNA for the Analysis of Similarities in Twitter BehavioursabstractRecently, DNA-inspired online behavioral modeling and analysis techniques have been proposed and successfully applied to a broad range of tasks. In this paper, we employ a DNA-inspired technique to investigate the fundamental laws that drive the occurrence of similarities among Twitter users. The achieved results are multifold. First, we demonstrate that, despite apparently showing little to no similarities, the online behaviors of Twitter users are far from being uniformly random. Then, we perform a set of simulations to benchmark different behavioral models and to identify the models that better resemble human behaviors in Twitter. Finally, we demonstrate that the number and the extent of behavioral similarities within a group of Twitter users obey a log-normal distribution. Our results shed light on the fundamental properties that drive behaviors of groups of Twitter users, through the lenses of DNA-inspired behavioral modeling techniques. Our datasets are publicly available to the scientific community to further explore analytics of online behaviors. Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
DSAA | 2 |
| 2017 | CONNECT: CONtextual NamE disCovery for blockchain-based services in the IoTabstractThe Internet of Things is gaining momentum thanks to the provided vision of seamlessly interconnected devices. However, a unified way to discover and to interact with the surrounding smart environment is missing. As an outcome, we have been assisting to the development of heterogeneous ecosystems, where each service provider adopts its own protocol- thus preventing IoT devices from interacting when belonging to different providers. And, the same is happening again for the blockchain technology which provides a robust and trusted way to accomplish tasks -unfortunately not providing interoperability thus creating the same heterogeneous ecosystems above highlighted. In this context, the fundamental research question we address is how do we find things or services in the Internet of Things. In this paper, we propose the first IoT discovery approach which provides an answer to the above question by exploiting hierarchical and universal multi-layered blockchains. Our approach does neither define new standards nor force service providers to change their own protocol. On the contrary, it leverages the existing and publicly available information obtained from each single blockchain to have a better knowledge of the surrounding environment. The proposed approach is detailed and discussed with the support of relevant use cases. Vanesa Daza, Roberto Di Pietro, Ivan Klimek, Matteo Signorini |
ICC | 2 |
| 2017 | HyBIS: Advanced Introspection for Effective Windows Guest Protection
Roberto Di Pietro, Federico Franzoni, Flavio Lombardi |
SEC | 1 |
| 2017 | SLAP: Secure Lightweight Authentication Protocol for Resource-constrained Devices
Giulio Aliberti, Roberto Di Pietro, Stefano Guarino |
SECRYPT | 2 |
| 2017 | Enabling broadcast communications in presence of jamming via probabilistic pairing
Roberto Di Pietro, Gabriele Oligeri |
Comput. Networks | 1 |
| 2017 | Epidemic data survivability in Unattended Wireless Sensor Networks: New models and results
Giulio Aliberti, Roberto Di Pietro, Stefano Guarino |
J. Netw. Comput. Appl. | 2 |
| 2016 | Logical key hierarchy for groups management in Distributed Online Social NetworkabstractDistributed Online Social Networks (DOSNs) have recently been proposed to shift the control over user data from a unique entity to the users of the DOSN themselves. In this paper, we focus our attention on the problem of privacy preserving content sharing to a large group of users of the DOSNs. Several solutions, based on cryptographic techniques, have been recently proposed. The main challenge here is the definition of a scalable and decentralized approach that: i) minimizes the re-encryption of the contents published in a group when the composition of the group changes and ii) enables a fast distribution of the cryptographic keys to all the members (n) of a group, each time a new user is added or removed from the group by the group owner. Our solution achieves the above goals, providing performance unattained by our competitors. In particular, our approach requires only O(d·logn) encryption operations when the group membership changes (eviction), and only O(2·logn) when a join occurs (where d is an input parameter of the system). The effectiveness of our approach is evaluated by an experimental campaign carried out over a set of traces from a real online social network. Andrea De Salve, Roberto Di Pietro, Paolo Mori, Laura Ricci |
ISCC | 2 |
| 2016 | Reliable and perfectly secret communication over the generalized Ozarow-Wyner's wire-tap channel
Giulio Aliberti, Roberto Di Pietro, Stefano Guarino |
Comput. Networks | 2 |
| 2016 | CURE - Towards enforcing a reliable timeline for cloud forensics: Model, architecture, and experiments
Roberto Battistoni, Roberto Di Pietro, Flavio Lombardi |
Comput. Commun. | 2 |
| 2016 | Proof of ownership for deduplication systems: A secure, scalable, and efficient solution
Roberto Di Pietro, Alessandro Sorniotti |
Comput. Commun. | 1 |
| 2016 | FRoDO: Fraud Resilient Device for Off-Line Micro-PaymentsabstractCredit and debit card data theft is one of the earliest forms of cybercrime. Still, it is one of the most common nowadays. Attackers often aim at stealing such customer data by targeting the Point of Sale (for short, PoS) system, i.e. the point at which a retailer first acquires customer data. Modern PoS systems are powerful computers equipped with a card reader and running specialized software. Increasingly often, user devices are leveraged as input to the PoS. In these scenarios, malware that can steal card data as soon as they are read by the device has flourished. As such, in cases where customer and vendor are persistently or intermittently disconnected from the network, no secure on-line payment is possible. This paper describes FRoDO, a secure off-line micro-payment solution that is resilient to PoS data breaches. Our solution improves over up to date approaches in terms of flexibility and security. To the best of our knowledge, FRoDO is the first solution that can provide secure fully off-line payments while being resilient to all currently known PoS breaches. In particular, we detail FRoDO architecture, components, and protocols. Further, a thorough analysis of FRoDO functional and security properties is provided, showing its effectiveness and viability. Vanesa Daza, Roberto Di Pietro, Flavio Lombardi, Matteo Signorini |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2016 | CUDA Leaks: A Detailed Hack for CUDA and a (Partial) FixabstractGraphics processing units (GPUs) are increasingly common on desktops, servers, and embedded platforms. In this article, we report on new security issues related to CUDA, which is the most widespread platform for GPU computing. In particular, details and proofs-of-concept are provided about novel vulnerabilities to which CUDA architectures are subject. We show how such vulnerabilities can be exploited to cause severe information leakage. As a case study, we experimentally show how to exploit one of these vulnerabilities on a GPU implementation of the AES encryption algorithm. Finally, we also suggest software patches and alternative approaches to tackle the presented vulnerabilities. Roberto Di Pietro, Flavio Lombardi, Antonio Villani |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2016 | Alterdroid: Differential Fault Analysis of Obfuscated Smartphone MalwareabstractMalware for smartphones has rocketed over the last years. Market operators face the challenge of keeping their stores free from malicious apps, a task that has become increasingly complex as malware developers are progressively using advanced techniques to defeat malware detection tools. One such technique commonly observed in recent malware samples consists of hiding and obfuscating modules containing malicious functionality in places that static analysis tools overlook (e.g., within data objects). In this paper, we describe Alterdroid, a dynamic analysis approach for detecting such hidden or obfuscated malware components distributed as parts of an app package. The key idea in Alterdroid consists of analyzing the behavioral differences between the original app and a number of automatically generated versions of it, where a number of modifications (faults) have been carefully injected. Observable differences in terms of activities that appear or vanish in the modified app are recorded, and the resulting differential signature is analyzed through a pattern-matching process driven by rules that relate different types of hidden functionalities with patterns found in the signature. A thorough justification and a description of the proposed model are provided. The extensive experimental results obtained by testing Alterdroid over relevant apps and malware samples support the quality and viability of our proposal. Guillermo Suarez-Tangil, Juan Tapiador, Flavio Lombardi, Roberto Di Pietro |
IEEE Trans. Mob. Comput. | 4 |
| 2015 | VISIO: A Visual Approach for Singularity Detection in Recommendation Systems
Alessandro Colantonio, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi |
TrustBus | 2 |
| 2015 | Freedom of speech: thwarting jammers via a probabilistic approachabstractIn this paper, we introduce a lightweight, fully distributed, and probabilistic protocol---Freedom of Speech (FoS)---that assures the delivery of a message to be broadcast (to N nodes) notwithstanding the presence of a powerful jammer. FoS enjoys several features when compared to competing schemes: it requires each node to store just N symmetric pairwise keys; node joining and node eviction require just minimal intervention on the already operating nodes; and, it is highly efficient in terms of required computation and message exchange. Roberto Di Pietro, Gabriele Oligeri |
WISEC | 1 |
| 2015 | ESC: An efficient, scalable, and crypto-less solution to secure wireless networks
Roberto Di Pietro, Gabriele Oligeri |
Comput. Networks | 1 |
| 2015 | Fame for sale: Efficient detection of fake Twitter followersabstractFake followers are those Twitter accounts specifically created to inflate the number of followers of a target account. Fake followers are dangerous for the social platform and beyond, since they may alter concepts like popularity and influence in the Twittersphere—hence impacting on economy, politics, and society. In this paper, we contribute along different dimensions. First, we review some of the most relevant existing features and rules (proposed by Academia and Media) for anomalous Twitter accounts detection. Second, we create a baseline dataset of verified human and fake follower accounts. Such baseline dataset is publicly available to the scientific community. Then, we exploit the baseline dataset to train a set of machine-learning classifiers built over the reviewed rules and features. Our results show that most of the rules proposed by Media provide unsatisfactory performance in revealing fake followers, while features proposed in the past by Academia for spam detection provide good results. Building on the most promising features, we revise the classifiers both in terms of reduction of overfitting and cost for gathering the data needed to compute the features. The final result is a novel Class A classifier, general enough to thwart overfitting, lightweight thanks to the usage of the less costly features, and still able to correctly classify more than 95% of the accounts of the original training set. We ultimately perform an information fusion-based sensitivity analysis, to assess the global sensitivity of each of the features employed by the classifier. The findings reported in this paper, other than being supported by a thorough experimental methodology and interesting on their own, also pave the way for further investigation on the novel issue of fake Twitter followers. Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
Decis. Support Syst. | 2 |
| 2015 | EXPEDITE: EXPress closED ITemset Enumeration
Giulio Aliberti, Alessandro Colantonio, Roberto Di Pietro, Riccardo Mariani |
Expert Syst. Appl. | 3 |
| 2015 | AntiCheetah: Trustworthy computing in an outsourced (cheating) environment
Roberto Di Pietro, Flavio Lombardi, Fabio Martinelli, Daniele Sgandurra |
Future Gener. Comput. Syst. | 1 |
| 2015 | Silence is Golden: Exploiting Jamming and Radio Silence to CommunicateabstractJamming techniques require only moderate resources to be deployed, while their effectiveness in disrupting communications is unprecedented. In this article, we introduce several contributions to jamming mitigation. In particular, we introduce a novel adversary model that has both (unlimited) jamming reactive capabilities as well as powerful (but limited) proactive jamming capabilities. Under this adversary model, to the best of our knowledge more powerful than any other adversary model addressed in the literature, the communication bandwidth provided by current anti-jamming solutions drops to zero. We then present Silence is Golden ( SiG ): a novel anti-jamming protocol that, introducing a tunable, asymmetric communication channel, is able to mitigate the adversary capabilities, enabling the parties to communicate. For instance, with SiG it is possible to deliver a 128-bits-long message with a probability greater than 99% in 4096 time slots despite the presence of a jammer that jams all on-the-fly communications and 74% of the silent radio spectrum—while competing proposals simply fail. Moreover, when SiG is used in a scenario in which the adversary can jam only a subset of all the available frequencies, performance experiences a boost: a 128-bits-long message is delivered within just 17 time slots for an adversary able to jam 90% of the available frequencies. We present a thorough theoretical analysis for the solution, which is supported by extensive simulation results, showing the viability of our proposal. Roberto Di Pietro, Gabriele Oligeri |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2015 | Provable Storage Medium for Data Storage OutsourcingabstractIn remote storage services, delays in the time to retrieve data can cause economic losses to the data owners. In this paper, we address the problem of properly establishing specific clauses in the service level agreement (SLA), intended to guarantee a short and predictable retrieval time. Based on the rationale that the retrieval time mainly depends on the storage media used at the server side, we introduce the concept of Provable Storage Medium (PSM), to denote the ability of a user to efficiently verify that the provider is complying to this aspect of the SLA. We propose PSM as an extension of Provable Data Possession (PDP): embedding challenge-response PDP schemes with measurements of the response time, both properties can be enforced without any need for the user to locally store nor download her data. We describe a realistic implementation of PSM in a scenario where data should be stored both in RAM and HDD. A thorough analysis shows that, even for relatively small challenges, the total time to compute and deliver the response is sensibly affected by the remarkable difference in the access time of the two supports. An extensive simulation campaign confirms the quality and viability of our proposal. Stefano Guarino, Eyüp S. Canlar, Mauro Conti, Roberto Di Pietro, Agusti Solanas |
IEEE Trans. Serv. Comput. | 4 |
| 2014 | FORCE - Fully Off-line secuRe CrEdits for Mobile Micro PaymentsabstractPayment schemes based on mobile devices are expected to supersede traditional electronic payment approaches in the next few years. However, current solutions are limited in that protocols require at least one of the two parties to be on-line, i.e. connected either to a trusted third party or to a shared database. Indeed, in cases where customer and vendor are persistently or intermittently disconnected from the network, any on-line payment is not possible. This paper introduces FORCE, a novel mobile micro payment approach where all involved parties can be fully off-line. Our solution improves over state-of-the-art approaches in terms of payment flexibility and security. In fact, FORCE relies solely on local data to perform the requested operations. Present paper describes FORCE architecture, components and protocols. Further, a thorough analysis of its functional and security properties is provided showing its effectiveness and viability. Vanesa Daza, Roberto Di Pietro, Flavio Lombardi, Matteo Signorini |
SECRYPT | 2 |
| 2014 | A Lot of Slots - Outliers Confinement in Review-Based Systems
Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi |
WISE (1) | 1 |
| 2014 | Security in wireless ad-hoc networks - A survey
Roberto Di Pietro, Stefano Guarino, Nino Vincenzo Verde, Josep Domingo-Ferrer |
Comput. Commun. | 1 |
| 2014 | CloRExPa: Cloud resilience via execution path analysis
Roberto Di Pietro, Flavio Lombardi, Matteo Signorini |
Future Gener. Comput. Syst. | 1 |
| 2014 | Clone wars: Distributed detection of clone attacks in mobile WSNs
Mauro Conti, Roberto Di Pietro, Angelo Spognardi |
J. Comput. Syst. Sci. | 2 |
| 2013 | CREPUSCOLO: A collusion resistant privacy preserving location verification systemabstractIn location-sensitive applications (e.g. location-based access control, and location-based social networks), users often benefit from being at a certain location. These benefits are incentives for users to cheat about their current location, in order to get unauthorized access to resources and services provided by location-sensitive applications. To deal with this issue, we propose CREPUSCOLO, a collusion resistant and privacy preserving location verification system. In CREPUSCOLO, we use “location-proofs” collected from co-located mobile devices, which can be endorsed by a “token” acquired from a trusted Token Provider. In fact, location-proofs endorsed by tokens provide the resiliency against collusion attacks, because this combination can prove that a certain mobile device was at a certain location at a specific time. CREPUSCOLO also protects the source location privacy by enforcing the usage of periodically changing pseudonyms. Extensive simulations show that CREPUSCOLO is effective in detecting collusion attacks even under very conservative hypothesis. For instance, with just 11 Token Providers spread over a 121 km2area characterized by a very low density of cooperating devices, 90% of collusion attacks are detected. Eyüp S. Canlar, Mauro Conti, Bruno Crispo, Roberto Di Pietro |
CRiSIS | 4 |
| 2013 | MASS: An efficient and secure broadcast authentication scheme for resource constrained devicesabstractMessage authentication for resource constrained devices is a challenging topic. Indeed, given the scarceness of on-board resources, solutions that do not rely on asymmetric key cryptography are in demand. A few solutions to address this issue have been proposed, and some have gained the status of state of the art thanks to their effectiveness and efficiency. However, even if state of the art solutions do provide sender-receiver on-the-fly message authentication, they are not able to tackle a few relevant attacks on received messages when the time dimension is taken into account. In particular, we first introduce two types of attacks: the switch command attack (where an adversary pretends to “switch” two messages over time-that is, altering the relative time ordering), and the drop command attack (where an adversary could pretend not having received a message previously sent from the legitimate sender). We then propose a new solution for broadcast authentication that copes with the above introduced attacks: MASS. Our analysis shows that MASS is effective in detecting both switch command and drop command attacks. Wafa Ben Jaballah, Mauro Conti, Roberto Di Pietro, Mohamed Mosbah 0001, Nino Vincenzo Verde |
CRiSIS | 3 |
| 2013 | Uniqueness of the file systems genome: Supporting arguments and massive experimental measurementsabstractThis paper provides evidence of a distinguished feature of file systems, that we call File System Genome. Such a feature is originated by the locations where the file blocks are placed on the mass-storage device by the operating system during the installation procedure. It appears from our study that the File System Genome is a distinctive feature of each operating system installation. In particular, our extensive set of experiments shows that the installation of the same operating system on two identical hardware configurations generates two different File System Genomes. Further, the application of sound information theory tools, such as min entropy, show that the differences between two File System Genome are considerably relevant. The results provided in this paper constitute the scientific basis for a number of applications in various fields of information technology, such as devices' identification and security. Roberto Di Pietro, Luigi V. Mancini, Antonio Villani, Domenico Vitali |
CRiSIS | 1 |
| 2013 | Data confidentiality and availability via secret sharing and node mobility in UWSNabstractIn Mobile Unattended Wireless Sensor Networks (MUWSNs), nodes sense the environment and store the acquired data until the arrival of a trusted data sink. In this paper, we address the fundamental issue of quantifying to which extent secret sharing schemes, combined with nodes mobility, can help in assuring data availability and confidentiality. We provide accurate analytical results binding the fraction of the network accessed by the sink and the adversary to the amount of information they can successfully recover. Extensive simulations support our findings. Roberto Di Pietro, Stefano Guarino |
INFOCOM | 1 |
| 2013 | Confidentiality and availability issues in Mobile Unattended Wireless Sensor NetworksabstractIn Mobile Unattended Wireless Sensor Networks (MUWSNs), nodes sense the environment and store the acquired data until the arrival of a trusted data sink. MUWSNs, other than being a reference model for an increasing number of military and civilian applications, also capture a few important characteristics of emerging computing paradigms like Participatory Sensing (PS). In this paper, we start by identifying the main features and issues of MUWSNs, revising the related work in the area and highlighting their shortcomings. We then propose a new approach based on secret sharing and information diffusion to improve data integrity and confidentiality, and present experimental results confirming the effectiveness of this solution. The rationale is that information sharing among neighboring nodes, combined with nodes mobility, helps distributing the information into the network in a way that, at the same time, facilitates data recovering and is resilient to data loss or stealing. This is a first step towards the general objective of providing closed results about how secret sharing schemes and nodes mobility can help in assuring data security using local communications only, and understanding how to set system parameters to achieve the desired trade-off between confidentiality and availability. Roberto Di Pietro, Stefano Guarino |
WOWMOM | 1 |
| 2013 | Track me if you can: Transparent obfuscation for Location based ServicesabstractAlthough Location-based Services (LBSs) offer evident advantages to their users, many privacy concerns are sought when user tracking data are shared with the service provider. Existing privacy enhancing solutions (e.g. k-anonymity) usually degrade service precision, and also require the collaboration of the service provider-this latter one not always willing to lose control over the user's location data. In this paper, we propose a solution that is able to obfuscate the user's path to the service provider, while preserving (for the LBS) the capability to compute a few functions-useful for the user-over the obfuscated path. In particular, we provide several contributions: first, we formalize the concept of obfuscation function, and we propose a solution that provides user privacy while allowing users to continue leveraging the services offered by the service provider. Moreover, we formally prove the privacy preserving properties of our approach. Finally, an extensive experimental campaign supports the feasibility of our approach, showing that the proposed solution can be efficiently implemented over mobile device. Roberto Di Pietro, Roberto Mandati, Nino Vincenzo Verde |
WOWMOM | 1 |
| 2013 | Titans' revenge: Detecting Zeus via its own flaws
Marco Riccardi, Roberto Di Pietro, Marta Palanques, Jorge Aguila Vila |
Comput. Networks | 2 |
| 2013 | Windows Mobile LiveSD Forensics
Eyüp S. Canlar, Mauro Conti, Bruno Crispo, Roberto Di Pietro |
J. Netw. Comput. Appl. | 4 |
| 2013 | Epidemic theory and data survivability in unattended wireless sensor networks: Models and gaps
Roberto Di Pietro, Nino Vincenzo Verde |
Pervasive Mob. Comput. | 1 |
| 2013 | COKE Crypto-Less Over-the-Air Key EstablishmentabstractIn this paper, we present a novel probabilistic protocol (COKE) to allow two wireless communicating parties to commit over-the-air (OTA) on a shared secret, even in the presence of a globally eavesdropping adversary. The proposed solution leverages no crypto but just plaintext messages exchange. Indeed, the security of the solution relies on the difficulty for the adversary to correctly identify, for each one-bit transmission, the sender of that bit-not its value, which is indeed exchanged in cleartext. Due to the low requirements of COKE (essentially, the capability to send a few wireless messages), it is particularly suited for resource constrained wireless devices (e.g., WNSs, wireless embedded systems), as well as for those scenarios where just energy saving is at premium, such as smartphones. Roberto Di Pietro, Gabriele Oligeri |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | United We Stand: Intrusion Resilience in Mobile Unattended WSNsabstractWireless Sensor Networks (WSNs) are susceptible to a wide range of attacks due to their distributed nature, limited sensor resources, and lack of tamper resistance. Once a sensor is corrupted, the adversary learns all secrets. Thereafter, most security measures become ineffective. Recovering secrecy after compromise requires either help from a trusted third party or access to a source of high-quality cryptographic randomness. Neither is available in Unattended Wireless Sensor Networks (UWSNs), where the sink visits the network periodically. Prior results have shown that sensor collaboration is an effective but expensive means of obtaining probabilistic intrusion resilience in static UWSNs. In this paper, we focus on intrusion resilience in Mobile Unattended Wireless Sensor Networks (μUWSNs), where sensors move according to some mobility models. Note that such a mobility feature could be independent from security (e.g., sensors move to improve area coverage). We define novel security metrics to evaluate intrusion resilience protocols for sensor networks. We also propose a cooperative protocol that - by leveraging sensor mobility - allows compromised sensors to recover secure state after compromise. This is obtained with very low overhead and in a fully distributed fashion. Thorough analysis and extensive simulations support our findings. Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik |
IEEE Trans. Mob. Comput. | 1 |
| 2012 | Boosting efficiency and security in proof of ownership for deduplicationabstractDeduplication is a technique used to reduce the amount of storage needed by service providers. It is based on the intuition that several users may want (for different reasons) to store the same content. Hence, storing a single copy of these files is sufficient. Albeit simple in theory, the implementation of this concept introduces many security risks. In this paper we address the most severe one: an adversary (who possesses only a fraction of the original file, or even just partially colluding with a rightful owner) claiming to possess such a file. The paper's contributions are manifold: first, we introduce a novel Proof of Ownership (POW) scheme that has all features of the state-of-the-art solution while incurring only a fraction of the overhead experienced by the competitor; second, the security of the proposed mechanisms relies on information theoretical (combinatoric) rather than computational assumptions; we also propose viable optimization techniques that further improve the scheme's performance. Finally, the quality of our proposal is supported by extensive benchmarking. Roberto Di Pietro, Alessandro Sorniotti |
AsiaCCS | 1 |
| 2012 | PRISM - Privacy-Preserving Search in MapReduce
Erik-Oliver Blass, Roberto Di Pietro, Refik Molva, Melek Önen |
Privacy Enhancing Technologies | 2 |
| 2012 | Secure Cloud Browser: Model and Architecture to Support Secure WEB NavigationabstractA Web browser is probably the main attack vector used by hackers. Solutions to browser's security are difficult to foresee, due to the influence of user-behaviour. In this paper, we show how to tackle the issue of securing web browsers introducing a Secure Cloud Browser (SCB) architecture. The rationale behind the SCB is to reduce browser vulnerability by transporting it to a remote secure environment, making it ephemeral and renovating it in a manner that is transparent to the user. Our scheme allows the user to browse a web application while source code is remotely interpreted. Further, obfuscation techniques are used to increase the lifetime of a browser session. Details and discussion over the SCB architecture are reported, while its implementation and assessment is undergoing work. Marta Palanques, Roberto Di Pietro, Carlos del Ojo, Marcel Malet, Miquel Marino, Toni Felguera |
SRDS | 2 |
| 2012 | Broadcast Authentication for Resource Constrained Devices: A Major Pitfall and Some SolutionsabstractBroadcast authentication is an important security mechanism for resource constrained devices, like Wireless Sensor Networks (WSNs). In this paper we revise how broadcast authentication has been enforced in this context, and we show that most of the current implementations (generally based on lightweight hash chain implementing time limited validity of the authentication property) leave open the possibility of a dreadful attack. We detail such an attack, and propose three different protocols to cope with it: PASS, TASS, and PTASS. We further analyze the overhead introduced by these protocols in terms of set-up, transmission overhead, and on device verification. Roberto Di Pietro, Fabio Martinelli, Nino Vincenzo Verde |
SRDS | 1 |
| 2012 | A business-driven decomposition methodology for role mining
Alessandro Colantonio, Roberto Di Pietro, Nino Vincenzo Verde |
Comput. Secur. | 2 |
| 2012 | Visual Role Mining: A Picture Is Worth a Thousand RolesabstractThis paper offers a new role engineering approach to Role-Based Access Control (RBAC), referred to as visual role mining. The key idea is to graphically represent user-permission assignments to enable quick analysis and elicitation of meaningful roles. First, we formally define the problem by introducing a metric for the quality of the visualization. Then, we prove that finding the best representation according to the defined metric is a NP-hard problem. In turn, we propose two algorithms: ADVISER and EXTRACT. The former is a heuristic used to best represent the user-permission assignments of a given set of roles. The latter is a fast probabilistic algorithm that, when used in conjunction with ADVISER, allows for a visual elicitation of roles even in absence of predefined roles. Besides being rooted in sound theory, our proposal is supported by extensive simulations run over real data. Results confirm the quality of the proposal and demonstrate its viability in supporting role engineering decisions. Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2012 | Self-healing in unattended wireless sensor networksabstractWireless sensor networks (WSNs) appeal to a wide range of applications that involve the monitoring of various physical phenomena. However, WSNs are subject to many threats. In particular, lack of pervasive tamper-resistant hardware results in sensors being easy targets for compromise. Having compromised a sensor, the adversary learns all the sensor secrets, allowing it to later encrypt/decrypt or authenticate messages on behalf of that sensor. This threat is particularly relevant in the novel unattended wireless sensor networks (UWSNs) scenario. UWSNs operate without constant supervision by a trusted sink. UWSN's unattended nature and increased exposure to attacks prompts the need for special techniques geared towards regaining security after being compromised. In this article, we investigate cooperative self-healing in UWSNs and propose various techniques to allow unattended sensors to recover security after compromise. Our techniques provide seamless healing rates even against a very agile and powerful adversary. The effectiveness and viability of our proposed techniques are assessed by thorough analysis and supported by simulation results. Finally, we introduce some real-world issues affecting UWSN deployment and provide some solutions for them as well as a few open problems calling for further investigation. Roberto Di Pietro, Di Ma 0001, Claudio Soriente, Gene Tsudik |
ACM Trans. Sens. Networks | 1 |
| 2011 | Epidemic data survivability in unattended wireless sensor networksabstractA recent research thread focused on Unattended Wireless Sensor Networks (UWSNs), that are characterized by the intermittent presence of the sink. An adversary can take advantage of this behavior trying to erase a piece of information sensed by the network before the sink collects it. Therefore, without a mechanism in place to assure data availability, the sink will not ever know that a datum has been compromised. In this paper, we adopt data replication to assure data survivability in UWSNs. In particular, we revisit an epidemic model and show that, even if the data replication process can be modelled as the spreading of a disease in a finite population, new problems that have not been discovered before arise: optimal parameters choice for the model do not assure the intended data survivability. The problem is complicated by the fact that it is driven by two conflicting parameters: On the one hand the flooding of the datum has to be avoided---due to the sensor resource constraints---, while on the other hand data survivability depends on the data replication rate. Using advanced probabilistic tools we achieve a theoretically sound result that assures at the same time: Data survivability, an optimal usage of sensors resources, and a fast and predictable collecting time. These results have been achieved in both the full visibility and the geometrical model. Finally, extensive simulation results support our findings. Roberto Di Pietro, Nino Vincenzo Verde |
WISEC | 1 |
| 2011 | Events privacy in WSNs: A new model and its applicationabstractA novel issue resource constrained Wireless Sensor Networks (WSNs) are affected by is context privacy. Indeed, while a few solutions do exist to provide data privacy to WSNs (i.e. to protect message confidentiality), providing context privacy (e.g. preventing an adversary to locate the source of a message) is still an open research problem. This paper attacks the issue providing several contributions. First, a formal model to reason about event privacy in WSNs is introduced. This model also captures dynamic events. Second, we introduce a new realistic class of mobile events a WSN can experience. These events become the target of our privacy preserving efforts. Third, we propose a privacy enforcing solution for the above class of events: the Unobservable Handoff Trajectory (UHT) Protocol. UHT is scalable and distributed. The analysis shows that it is both effective and efficient in terms of the induced overhead. It also minimizes the delay to notify the event sources location to the base station, while preserving the intended degree of privacy. Finally, extensive simulations confirm our findings. Stefano Ortolani, Mauro Conti, Bruno Crispo, Roberto Di Pietro |
WOWMOM | 4 |
| 2011 | Introducing epidemic models for data survivability in Unattended Wireless Sensor NetworksabstractOne of the most relevant issues pertaining UWSN is to guarantee a certain level of information survivability, even in presence of a powerful attacker. In this paper, we provide a preliminary assessment of epidemic-domain inspired approaches to model the information survivability in UWSN. In particular, we show that epidemic models can be used to set up the parameters that allow the information to survive, once estimated the maximal compromising power of the attacker. Further, we point out that the mere application of these models is not always the right choice. Indeed, it comes out that these deterministic models are not enough accurate, and “unlikely” events can cause the loss of the datum. Finally, we provide some final comments, as well as promising research directions. Roberto Di Pietro, Nino Vincenzo Verde |
WOWMOM | 1 |
| 2011 | Location privacy and resilience in wireless sensor networks querying
Roberto Di Pietro, Alexandre Viejo |
Comput. Commun. | 1 |
| 2011 | A new role mining framework to elicit business roles and to mitigate enterprise risk
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
Decis. Support Syst. | 2 |
| 2011 | Secure virtualization for cloud computing
Flavio Lombardi, Roberto Di Pietro |
J. Netw. Comput. Appl. | 2 |
| 2011 | An optimal probabilistic solution for information confinement, privacy, and security in RFID systems
Roberto Di Pietro, Refik Molva |
J. Netw. Comput. Appl. | 1 |
| 2011 | Intrusion-resilient integrity in data-centric unattended WSNs
Roberto Di Pietro, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
Pervasive Mob. Comput. | 1 |
| 2011 | Secure topology maintenance and events collection in WSNsabstractAbstract Topology Maintenance Protocols (TMPs) are key for operating Wireless Sensor Networks (WSNs). Their adoption serves a few goals, such as, to save energy, to avoid collisions in communications and to have an adequate number of nodes monitoring the environment—by alternating duty cycles with sleep cycles on the sensor nodes. While effectiveness of TMPs protocols is widely addressed, security is an overlooked feature. Indeed, while different TMPs have been presented in the literature, few of them address the security issues. In particular, only recently a secure TMP protocol that does not require pair‐wise node confidentiality has been proposed: Sec‐TMP. The aim of Sec‐TMP is to enforce event delivery to the Base Station while providing a standard topology maintenance service to the WSN. In this paper, we provide a thorough assessment of our previous preliminary proposal of Sec‐TMP, with particular reference to its effectiveness and security. First, we investigate the energy consumption introduced by TMPs protocols. Second, we show that Sec‐TMP performs well without any assumption neither on the show‐up time of data‐collecting node, nor on their mobility model. In particular, we test Sec‐TMP against a realistic unpredictable data‐collecting mobility scenario, that also brings in new security issues. A thorough security analysis of the proposed solutions to these new issues is also provided. Finally, extensive simulations support the quality of Sec‐TMP as for effectiveness and security. Copyright © 2011 John Wiley & Sons, Ltd. Mauro Conti, Roberto Di Pietro, Andrea Gabrielli, Luigi V. Mancini |
Secur. Commun. Networks | 2 |
| 2011 | Distributed Detection of Clone Attacks in Wireless Sensor NetworksabstractWireless Sensor Networks (WSNs) are often deployed in hostile environments where an adversary can physically capture some of the nodes, first can reprogram, and then, can replicate them in a large number of clones, easily taking control over the network. A few distributed solutions to address this fundamental problem have been recently proposed. However, these solutions are not satisfactory. First, they are energy and memory demanding: A serious drawback for any protocol to be used in the WSN-resource-constrained environment. Further, they are vulnerable to the specific adversary models introduced in this paper. The contributions of this work are threefold. First, we analyze the desirable properties of a distributed mechanism for the detection of node replication attacks. Second, we show that the known solutions for this problem do not completely meet our requirements. Third, we propose a new self-healing, Randomized, Efficient, and Distributed (RED) protocol for the detection of node replication attacks, and we show that it satisfies the introduced requirements. Finally, extensive simulations show that our protocol is highly efficient in communication, memory, and computation; is much more effective than competing solutions in the literature; and is resistant to the new kind of attacks introduced in this paper, while other solutions are not. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | Robust and efficient authentication of video stream broadcastingabstractWe present a novel video stream authentication scheme which combines signature amortization by means of hash chains and an advanced watermarking technique. We propose a new hash chain construction, the Duplex Hash Chain, which allows us to achieve bit-by-bit authentication that is robust to low bit error rates. This construction is well suited for wireless broadcast communications characterized by low packet losses such as in satellite networks. Moreover, neither hardware upgrades nor specific end-user equipment are needed to enjoy the authentication services. The computation overhead experienced on the receiver only sums to two hashes per block of pictures and one digital signature verification for the whole received stream. This overhead introduces a provably negligible decrease in video quality. A thorough analysis of the proposed solution is provided in conjunction with extensive simulations. Gabriele Oligeri, Stefano Chessa, Roberto Di Pietro, Gaetano Giunta |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2010 | Evaluating the Risk of Adopting RBAC Roles
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
DBSec | 2 |
| 2010 | CUDACS: Securing the Cloud with CUDA-Enabled Secure Virtualization
Flavio Lombardi, Roberto Di Pietro |
ICICS | 2 |
| 2010 | Time Warp: How Time Affects Privacy in LBSs
Luciana Marconi, Roberto Di Pietro, Bruno Crispo, Mauro Conti |
ICICS | 2 |
| 2010 | Intrusion-Resilience in Mobile Unattended WSNsabstractWireless Sensor Networks (WSNs) are susceptible to a wide range of attacks due to their distributed nature, limited sensor resources and lack of tamper-resistance. Once a sensor is corrupted, the adversary learns all secrets and (even if the sensor is later released) it is very difficult for the sensor to regain security, i.e., to obtain intrusion-resilience. Existing solutions rely on the presence of an on-line trusted third party, such as a sink, or on the availability of secure hardware on sensors. Neither assumption is realistic in large-scale Unattended WSNs (UWSNs), characterized by long periods of disconnected operation and periodic visits by the sink. In such settings, a mobile adversary can gradually corrupt the entire network during the intervals between sink visits. As shown in some recent work, intrusion-resilience in UWSNs can be attained (to a degree) via cooperative self-healing techniques. In this paper, we focus on intrusion-resilience in Mobile Unattended Wireless Sensor Networks (¿UWSNs) where sensors move according to some mobility model. We argue that sensor mobility motivates a specific type of adversary and defending against it requires new security techniques. Concretely, we propose a cooperative protocol that - by leveraging sensor mobility - allows compromised sensors to recover secure state after compromise. This is obtained with very low overhead and in a fully distributed fashion. We provide a thorough analysis of the proposed protocol and support it by extensive simulation results. Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik |
INFOCOM | 1 |
| 2010 | Mining Business-Relevant RBAC States through Decomposition
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
SEC | 2 |
| 2010 | CED2: Communication Efficient Disjointness Decision
Luciana Marconi, Mauro Conti, Roberto Di Pietro |
SecureComm | 3 |
| 2010 | CReW: Cloud Resilience for Windows Guests through Monitored VirtualizationabstractClouds are complex systems subject to an increasing number of anomalies and threats. In this paper we briefly revisit the issues related to Windows guest cloud service resilience and later provide some preliminary results on the resilience of Windows cloud guests via virtualization. In particular, we propose an architecture, Cloud Resilience for Windows (CReW). CReW can transparently monitor guest Windows VMs and can also react to both security breaches and system integrity violation, improving the dependability of cloudified Windows systems. CReW can also improve resilience from software misconfiguration by restoring the guest latest safe state. Effectiveness and performance of a CReW prototype have been evaluated, obtained results show the feasibility of such a system. Flavio Lombardi, Roberto Di Pietro, Claudio Soriente |
SRDS | 2 |
| 2010 | Securing Mobile Unattended WSNs against a Mobile AdversaryabstractOne important factor complicating security in Wireless Sensor Networks (WSNs) is lack of inexpensive tamper-resistant hardware in commodity sensors. Once an adversary compromises a sensor, all memory and forms of storage become exposed, along with all secrets. Thereafter, any cryptographic remedy ceases to be effective. Regaining sensor security after compromise (i.e., intrusion-resilience) is a formidable challenge. Prior approaches rely on either (1) the presence of an on-line trusted third party (sink), or (2) the availability of a True Random Number Generator (TRNG) on each sensor. Neither assumption is realistic in large-scale Unattended Wireless Sensor Networks (UWSNs) composed of low-cost commodity sensors. periodic visits by the sink. Previous work has demonstrated that sensor collaboration is an effective, yet expensive, means of attaining intrusion-resilience in UWSNs. In this paper, we explore intrusion resilience in Mobile UWSNs in the presence of a powerful mobile adversary. We show how the choice of the sensor mobility model influences intrusion resilience with respect to this adversary. We also explore self healing protocols that require only local communication. Results indicate that sensor density and neighborhood variability are the two key parameters affecting intrusion resilience. Our findings are supported by extensive analyses and simulations. Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik |
SRDS | 1 |
| 2010 | Taming role mining complexity in RBAC
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
Comput. Secur. | 2 |
| 2010 | Concise: Compressed 'n' Composable Integer Set
Alessandro Colantonio, Roberto Di Pietro |
Inf. Process. Lett. | 2 |
| 2010 | Hierarchies of keys in secure multicast communicationsabstractThis work considers key management for secure multicast in the Logical Key Hierarchy (LKH) model and proposes a methodology to establish the minimal key bit length that guarantees a specified degree of confidentiality for the multicast communications managed within this model. We also introduce the concepts of information lifetime and information dependence to formalize the intuition that keys should be longer, and thus stronger, when used to encrypt “important” information, that is information (including other keys) that need to be kept confidential for a longer period. Then, these concepts are used to build a formal theory that is applied to set the correct bit length of every key in the system in such a way to guarantee the prescribed degree of confidentiality of the multicast messages. Quite surprisingly, we formally show that not all the keys in the LKH hierarchy should have the same length; this observation, besides being of theoretical interest, also leads to substantial savings in terms of memory, computation, and bandwidth. The theory we develop to obtain these results can be useful in other contexts as well. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
J. Comput. Secur. | 1 |
| 2010 | eRIPP-FS: Enforcing privacy and security in RFIDabstractAbstract In RFID systems addressing security issues, many authentication techniques require the tag to keep some sort of synchronization with the reader. In particular, this is true in those proposals that leverage hash chains. When the reader and the tag get de‐synchronized, possibly by an attacker, this paves the way to several denial of service (DoS) attacks, as well as threatening privacy (e.g.,viathetiming attack). Even if de‐synchronization happens for non‐malicious causes, this event has a negative effect on performances (for instance, slowing down the authentication process). In this paper, we provide a solution to cope with the de‐synchronization between the tag and the reader when hash chains are employed. In particular, our solution relies on mutual reader‐tag authentication, achievedviahash traversal and Merkle tree techniques. We show that this techniques applied to an existing security protocol for RFID systems, such as RIPP‐FS, make timing attacks hard to succeed. Moreover, the proposed solutions can be transparently and independently adopted by similar security protocols as well to thwart timing attack and/or to provide reader‐tag mutual authentication. Finally, extensive simulations show that our proposal introduces a negligible overhead to recover de‐synchronization. Copyright © 2009 John Wiley & Sons, Ltd. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Angelo Spognardi |
Secur. Commun. Networks | 2 |
| 2009 | A formal framework to elicit roles with business meaning in RBAC systemsabstractThe role-based access control (RBAC) model has proven to be cost effective to reduce the complexity and costs of ac-cess permission management. To maximize the advantages offered by RBAC, the role engineering discipline has been introduced. A viable approach is to explore current applica-tions and systems to find de facto roles embedded in existing user permissions, leading to what is usually referred to as role mining. However, a key problem that has not yet been adequately addressed by existing role mining approaches is how to propose roles that have business meaning. In order to do this, we provide a new formal framework that also enjoys practical relevance. In particular, the proposed framework leverages business information—such as business processes and organization structure—to implement role mining algo-rithms. Our key observation is that a role is likely to be meaningful from a business perspective when it involves ac-tivities within the same business process or organizational units within the same branch. To measure the “spreading” of a role among business processes or organization structure, we resort to centrality indices. Such indices are used in our cost-driven approach during the role mining process. Fi-nally, we illustrate the application of the framework through a few examples. Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
SACMAT | 2 |
| 2009 | Mining Stable Roles in RBAC
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
SEC | 2 |
| 2009 | A Probabilistic Bound on the Basic Role Mining Problem and Its Applications
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Vincenzo Verde |
SEC | 2 |
| 2009 | Sec-TMP: A Secure Topology Maintenance Protocol for Event Delivery Enforcement in WSN
Andrea Gabrielli, Mauro Conti, Roberto Di Pietro, Luigi V. Mancini |
SecureComm | 3 |
| 2009 | Collaborative authentication in unattended WSNsabstractAn unattended wireless sensor network (UWSN) might collect valuable data representing an attractive target for the adversary. Since a sink visits the network infrequently, unattended sensors cannot immediately off-load data to some safe external entity. With sufficient time between sink visits, a powerful mobile adversary can easily compromise sensor-collected data. Roberto Di Pietro, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
WISEC | 1 |
| 2009 | Playing hide-and-seek with a focused mobile adversary in unattended wireless sensor networks
Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
Ad Hoc Networks | 1 |
| 2009 | Privacy-preserving robust data aggregation in wireless sensor networksabstractAbstract In‐network data aggregationin wireless sensor networks (WSNs) is a technique aimed at reducing the communication overhead—sensed data are combined into partial results at intermediate nodes during message routing. However, in the above technique, some sensor nodes need to send their individual sensed values to an aggregator node, empowered with the capability to decrypt the received data to perform a partial aggregation. This scenario raises privacy concerns in applications like personal health care and the military surveillance. A few other solutions exist where the data are not disclosed to the aggregator (e.g., using privacy homomorphism (PH)), but these solutions are not robust to node or communication failure. The contributions of this paper are two‐fold: first, we design a private data aggregation protocol that does not leak individual sensed values during the data aggregation process. In particular, neither the base station (BS) nor the other nodes are able to compromise the privacy of an individual node's sensed value. Second, the proposed protocol is robust to data‐loss; if there is a node‐failure or communication failure, the protocol is still able to compute the aggregate and to report to the base station the number of nodes that participated in the aggregation. To the best of our knowledge, our scheme is the first one that efficiently addresses the above issues all at once. Copyright © 2009 John Wiley & Sons, Ltd. Mauro Conti, Lei Zhang 0004, Sankardas Roy, Roberto Di Pietro, Sushil Jajodia, Luigi V. Mancini |
Secur. Commun. Networks | 4 |
| 2009 | Confidentiality and integrity for data aggregation in WSN using peer monitoringabstractAbstract Hop‐by‐hop data aggregation is a very important technique used to reduce the communication overhead and energy expenditure of sensor nodes during the process of data collection in a wireless sensor network (WSN). However, the unattended nature of WSNs calls for data aggregation techniques to be secure. Indeed, sensor nodes can be compromised to mislead the base station (BS) by injecting bogus data into the network during both forwarding and aggregation of data. Moreover, data aggregation might increase the risk of confidentiality violations: If sensors close to the BS are corrupted, an adversary could easily access to the results of the ‘in network’ computation performed by the WSN. Further, nodes can also fail due to random and non‐malicious causes (e.g., battery exhaustion), hence availability should be considered as well. In this paper we tackle the above issues that affect data aggregation techniques by proposing a mechanism that: (i)provides both confidentiality and integrity of the aggregated data so that for any compromised sensor in the WSN the information acquired could only reveal the readings performed by a small, constant number of neighboring sensors of the compromised one; (ii) detects bogus data injection attempts; (iii) provides high resilience to sensor failures. Our protocol is based on the concept of delayed aggregation and peer monitoring and requires local interactions only. Hence, it is highly scalable and introduces small overhead; detailed analysis supports our findings. Copyright © 2009 John Wiley & Sons, Ltd. Roberto Di Pietro, Pietro Michiardi, Refik Molva |
Secur. Commun. Networks | 1 |
| 2009 | Data Security in Unattended Wireless Sensor NetworksabstractIn recent years, wireless sensor networks (WSNs) have been a very popular research topic, offering a treasure trove of systems, networking, hardware, security, and application-related problems. Much of prior research assumes that the WSN is supervised by a constantly present sink and sensors can quickly offload collected data. In this paper, we focus on unattended WSNs (UWSNs) characterized by intermittent sink presence and operation in hostile settings. Potentially lengthy intervals of sink absence offer greatly increased opportunities for attacks resulting in erasure, modification, or disclosure of sensor-collected data. This paper presents an in-depth investigation of security problems unique to UWSNs (including a new adversarial model) and proposes some simple and effective countermeasures for a certain class of attacks. Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
IEEE Trans. Computers | 1 |
| 2008 | Information Assurance in Critical Infrastructures via Wireless Sensor NetworksabstractInformation assurance in critical infrastructure is an issue that has been addressed generally focusing on real-time or quasi real-time monitoring of the critical infrastructure; so that action could be undertaken when anomalies arise, to avoid more severe consequences to the infrastructure. In this paper, we relax the hypothesis of intervening when anomalies are detected: we focus on sensed data survivability. Specifically, we study this problem in a specific critical infrastructure: pipelines. The problem we introduce is how to place sensors in such a way that the sensed data related to the monitoring of the pipeline will survive even in presence of a partial destruction of the infrastructure. The contributions of this paper are twofold. First, we introduce the problem of sensed data survivability in critical infrastructure. In this framework, the goal is to have the sensed data to survive to the infrastructure failure, so that the phenomena that lead to the failure could be better understood and possibly tackled in similar deployment. Second, we provide a model that allows to produce an optimal network topology with respect to the level of information assurance desired, while satisfying deployment constraints, such as available bandwidth and available energy of the sensors. We believe that the work addressed in this paper could foster further research in the field of information assurance in critical infrastructure. Michele Albano, Stefano Chessa, Roberto Di Pietro |
IAS | 3 |
| 2008 | A Linear-Time Multivariate Micro-aggregation for Privacy Protection in Uniform Very Large Data Sets
Agusti Solanas, Roberto Di Pietro |
MDAI | 2 |
| 2008 | Catch Me (If You Can): Data Survival in Unattended Sensor NetworksabstractUnattended sensor networks operating in hostile environments might collect data that represents a high-value target for the adversary. The unattended sensor's inability to off-load - in real time - sensitive data to a safe external entity makes it easy for the adversary to mount a focused attack aimed at eliminating certain target data. In order to facilitate survival of this data, sensors can collectively attempt to confuse the adversary by changing its location and content, i.e., by periodically moving the data around the network and encrypting it. In this paper, we focus on data survival in unattended sensor networks faced with an adversary intent on surgically destroying data which it considers to be of high value. After motivating the problem and considering several attack flavors, we propose several simple techniques and provide their detailed evaluation. Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
PerCom | 1 |
| 2008 | Gossip-based aggregate computation: computing faster with non address-oblivious schemesabstractIn this paper, we sketch a novel gossip-based scheme that allows all the nodes in an n-node overlay network to compute a common aggregate (MAX) of their values using O(n log log n) messages within O(log n) rounds of communication. Our result is achieved relaxing the hypothesis that nodes are address-oblivious, raising the question whether this paradigm (address-aware) is more expressive than the address-oblivious one. Roberto Di Pietro, Pietro Michiardi |
PODC | 1 |
| 2008 | A Live Digital Forensic system for Windows networks
Roberto Battistoni, Alessandro Di Biagio, Roberto Di Pietro, Matteo Formica, Luigi V. Mancini |
SEC | 3 |
| 2008 | Leveraging Lattices to Improve Role Mining
Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello |
SEC | 2 |
| 2008 | Scalable and efficient provable data possessionabstractStorage outsourcing is a rising trend which prompts a number of interesting security issues, many of which have been extensively investigated in the past. However, Provable Data Possession (PDP) is a topic that has only recently appeared in the research literature. The main issue is how to frequently, efficiently and securely verify that a storage server is faithfully storing its client's (potentially very large) outsourced data. The storage server is assumed to be untrusted in terms of both security and reliability. (In other words, it might maliciously or accidentally erase hosted data; it might also relegate it to slow or off-line storage.) The problem is exacerbated by the client being a small computing device with limited resources. Prior work has addressed this problem using either public key cryptography or requiring the client to outsource its data in encrypted form. Giuseppe Ateniese, Roberto Di Pietro, Luigi V. Mancini, Gene Tsudik |
SecureComm | 2 |
| 2008 | PEAC: a probabilistic, efficient, and resilient authentication protocol for broadcast communicationsabstractOne of the main challenges of securing broadcast communications is source authentication: to allow each receiver to verify the origin of the data. An ideal broadcast authentication protocol should be efficient for the sender and the receiver, have a small communication overhead, allow the receiver to authenticate each individual packet as soon as it is received (i.e. no buffering on the receivers), provide perfect robustness to packet loss, and scale to a large number of receivers. Andrea Cirulli, Roberto Di Pietro |
SecureComm | 2 |
| 2008 | POSH: Proactive co-Operative Self-Healing in Unattended Wireless Sensor NetworksabstractUnattended Wireless Sensor Networks (UWSNs) are composed of many small resource-constrained devices and operate autonomously, gathering data which is periodically collected by a visiting sink. Unattended mode of operation, deployment in hostile environments and value (or criticality) of collected data are some of the factors that complicate UWSN security. This paper makes two contributions. First, it explores a new threat model involving a mobile adversary who periodically compromises and releases sensors aiming to maximize its advantage and overall knowledge of collected data. Second, it constructs a self-healing protocol that allows sensors to continuously and collectively recover from compromise. The proposed protocol is both effective and efficient, as supported by analytical and simulation results. Roberto Di Pietro, Di Ma 0001, Claudio Soriente, Gene Tsudik |
SRDS | 1 |
| 2008 | Emergent properties: detection of the node-capture attack in mobile wireless sensor networksabstractOne of the most vexing problems in wireless sensor network security is the node capture attack. An adversary can capture a node from the network as the first step for further different types of attacks. For example, the adversary can collect all the cryptographic material stored in the node. Also, the node can be reprogrammed and re-deployed in the network in order to perform malicious activities. To the best of our knowledge no distributed solution has been proposed to detect a node capture in a mobile wireless sensor network. In this paper we propose an efficient and distributed solution to this problem leveraging emergent properties of mobile wireless sensor networks. In particular, we introduce two solutions: SDD, that does not require explicit information exchange between the nodes during the local detection, and CCD, a more sophisticated protocol that uses local node cooperation in addition to mobility to greatly improve performance. We also introduce a benchmark to compare these solutions with. Experimental results demonstrate the feasibility of our proposal. For instance, while the benchmark requires about 9,000 seconds to detect node captures, CDD requires less than 2,000 seconds. These results support our intuition that node mobility, in conjunction with a limited amount of local cooperation, can be used to detect emergent global properties. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
WISEC | 2 |
| 2008 | RFID security and privacy: long-term research or short-term tinkering?abstractRFID technology has raised a number of both real and imagined security and privacy fears and concerns. Since roughly 2001, a number of researchers have stepped up to the plate and proposed techniques for strengthening RFID security and privacy, while others have focused on attacking (and demonstrating weaknesses in) currently deployed RFID systems. Despite a few PhD theses devoted to this topic, it remains to be seen whether there are any new long-term fundamental issues involved in RFID security & privacy. Therefore, this panel's goal is to present and debate the panelists' diverse perspectives on the future (or lack thereof) of RFID security and privacy research. Gene Tsudik, Mike Burmester, Ari Juels, Alfred Kobsa, David Molnar, Roberto Di Pietro, Melanie R. Rieback |
WISEC | 6 |
| 2008 | A mechanism to enforce privacy in vehicle-to-infrastructure communication
Paolo Cencioni, Roberto Di Pietro |
Comput. Commun. | 2 |
| 2008 | Redoubtable Sensor NetworksabstractWe give, for the first time, a precise mathematical analysis of the connectivity and security properties of sensor networks that make use of the random predistribution of keys. We also show how to set the parameters---pool and key ring size---in such a way that the network is not only connected with high probability via secure links but also provably resilient, in the following sense: We formally show that any adversary that captures sensors at random with the aim of compromising a constant fraction of the secure links must capture at least a constant fraction of the nodes of the network. In the context of wireless sensor networks where random predistribution of keys is employed, we are the first to provide a mathematically precise proof, with a clear indication of parameter choice, that two crucial properties---connectivity via secure links and resilience against malicious attacks---can be obtained simultaneously. We also show in a mathematically rigorous way that the network enjoys another strong security property. The adversary cannot partition the network into two linear size components, compromising all the links between them, unless it captures linearly many nodes. This implies that the network is also fault tolerant with respect to node failures. Our theoretical results are complemented by extensive simulations that reinforce our main conclusions. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei, Alessandro Panconesi, Jaikumar Radhakrishnan |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2007 | Information Confinement, Privacy, and Security in RFID Systems
Roberto Di Pietro, Refik Molva |
ESORICS | 1 |
| 2007 | Towards threat-adaptive dynamic fragment replication in large scale distributed systemsabstractIn this paper, we consider new issues in building secure p2p file sharing systems. In particular, we define a powerful adversary model and consequently present the requirements to address when implementing a threat-adaptive secure file sharing system. We describe the main components of such a system: an early warning mechanism to perform pre-emptive actions against new vulnerabilities; a mechanism to sanitize corrupted nodes; a protocol to securely "migrate" data from non-safe nodes; and an efficient dynamic secret sharing mechanism. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
IPDPS | 1 |
| 2007 | VIPER: A vehicle-to-infrastructure communication privacy enforcement protocolabstractPrivacy-related issues are crucial for the wide diffusion of Vehicular Communications (VC). In particular, traffic analysis is one of the subtler threats to privacy in VC. In this paper we first briefly review current work in literature addressing privacy issues. Then we present VIPER: a Vehicle-to-infrastructure communication Privacy Enforcement pRotocol. VIPER is inspired to solutions provided for the Internet -mix- and cryptography-universal re- encryption. The protocol is shown to be resilient to traffic analysis attacks and analytical results suggest that it also performs well with respect to two key performance indicators: queue occupancy and message delivery time. Finally, simulation results support our analytical findings. Paolo Cencioni, Roberto Di Pietro |
MASS | 2 |
| 2007 | Secure k-Connectivity Properties of Wireless Sensor NetworksabstractA k-connected wireless sensor network (WSN) allows messages to be routed via one (or more) of at least k node-disjoint paths, so that even if some nodes along one of the paths fail, or are compromised, the other paths can still be used. This is a much desired feature in fault tolerance and security, k-connectivity in this context is largely a well-studied subject. When we apply the random key pre-distribution scheme to secure a WSN however, and only consider the paths consisting entirely of secure (encrypted and/or authenticated) links, we are concerned with the secure k-connectivity of the WSN. This notion of secure k-connectivity is relatively new and no results are yet available. The random key pre-distribution scheme has two important parameters: the key ring size and the key pool size. While it has been determined before the relation between these parameters and 1-connectivity, our work in k-connectivity is new. Using a recently introduced random graph model called kryptograph, we derive mathematical formulae to estimate the asymptotic probability of a WSN being securely k-connected, and the expected secure k-connectivity, as a function of the key ring size and the key pool size. Finally, our theoretical findings are supported by simulation results. Yee Wei Law, Li-Hsing Yen, Roberto Di Pietro, Marimuthu Palaniswami |
MASS | 3 |
| 2007 | A randomized, efficient, and distributed protocol for the detection of node replication attacks in wireless sensor networksabstractWireless sensor networks are often deployed in hostile environments, where anadversary can physically capture some of the nodes. Once a node is captured, the attackercan re-program it and replicate the node in a large number of clones, thus easily taking over the network. The detection of node replication attacks in a wireless sensor network is therefore a fundamental problem. A few distributed solutions have recently been proposed. However, these solutions are not satisfactory. First, they are energy and memory demanding: A serious drawback for any protocol that is to be used in resource constrained environment such as a sensor network. Further, they are vulnerable to specific adversary models introduced in this paper. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
MobiHoc | 2 |
| 2007 | Mobile Application Security for Video Streaming Authentication and Data Integrity Combining Digital Signature and Watermarking TechniquesabstractSatellite link presents peculiar characteristics like no packet reordering and low bit error rate. In this paper we leverage these characteristics combined with watermarking techniques to propose a novel authentication algorithm for multicast video streaming. This algorithm combines a single digital signature with a hash chain pre-computed on the transmitter side; the hash chain is embedded in the video stream by means of a watermarking technique. Our proposal shows several interesting features: authentication is enforced, as well as integrity of the received multicast stream; received blocks can be authenticated on the fly; no storage is required on the receiver side, except for the amount of memory needed to store a single hash; overhead computations required on the receiver sum up to single hash per block, while a digital signature verification is amortized over the whole received stream. Finally, note that the bandwidth overhead introduced is negligible, since the applied watermarking technique introduces virtually no modifications (at least, not recognizable by humans) on the original video stream pictures. Stefano Chessa, Roberto Di Pietro, Erina Ferro, Gaetano Giunta, Gabriele Oligeri |
VTC Spring | 2 |
| 2007 | ECCE: Enhanced cooperative channel establishment for secure pair-wise communication in wireless sensor networks
Mauro Conti, Roberto Di Pietro, Luigi V. Mancini |
Ad Hoc Networks | 2 |
| 2007 | Robust RSA distributed signatures for large-scale long-lived ad hoc networksabstractAd hoc environments are subject to tight security and architectural constraints, which call for distributed, adaptive, robust and efficient solutions. In this paper we propose a distributed signature protocol for large-scale long-lived ad hoc networks. The proposed protocol is based on RSA and a ne w (t,t)-secret sharing scheme. The nodes of the network are uniformly partitioned into t classes, and the nodes belonging to the same class are provided with the same share. Any t nodes, belonging to different classes, can collectively issue a signature, without any interaction. The scheme is at least as secure as any (t,n)-threshold scheme, i.e., an adversary can neither forge a signature nor disrupt the computation, unless it has compromised at least t nodes, belonging to different classes. Moreover, an attempt to disrupt the distributed service, by providing a fake signature share, would reveal the cheating node. Further, it is possible to easily increase the level of security, by shifting from a (t,t) to a (t+k,t+k) scheme, for a reasonable choice of parameter k, involving just a fraction of the nodes, so that the scheme is adaptive to the level of threat that the ad hoc network is subject to. Finally, the distributed signature protocol is efficient: the number of messages sent and received for generating a signature, as well as to increase the level of security, is small and both computations and memory required are small as well. Giorgio Zanin, Roberto Di Pietro, Luigi V. Mancini |
J. Comput. Secur. | 2 |
| 2006 | Addressing the shortcomings of one-way chainsabstractOne-way hash chains have been the preferred choice, over the symmetric and asymmetric key cryptography, in security setups where efficiency mattered; despite the ephemeral confidentiality and authentication they assure. Known constructions of one-way chains (for example, SHA-1 based), only ensure the forward secrecy and have limitations over their length i.e., a priori knowledge of chain's length is necessary before constructing it. In this paper, we will see how our approach, based on chameleon functions, leads to the generation of practically unbounded one-way chains with constant storage and computational requirements. We provide the construction and advantages of our proposal with the help of a secure group communication setup. We also provide the implementation details of our construction and argue its suitability for security setups, where one cannot a priori determine the longevity of the setup. Roberto Di Pietro, Luigi V. Mancini, Antonio Durante, Vishwas Patil |
AsiaCCS | 1 |
| 2006 | A formal framework for the performance analysis of P2P networks protocolsabstractIn this paper, we propose a formal framework based on the Markov chains to prove the performance of P2P protocols. Despite the proposal of several protocols for P2P networks, sometimes there is a lack of a formal demonstration of their performance: experimental simulations are the most used method to evaluate their performance, such as the average length of a lookup. In this paper, we introduce a versatile model for the analysis of P2P protocols. We employ this model to formally prove which is the average lookup length for two sample protocols: BaRT and Koorde. We verify the effectiveness of the proposed framework also via extensive simulations. Angelo Spognardi, Roberto Di Pietro |
IPDPS | 2 |
| 2006 | Requirements and Open Issues in Distributed Detection of Node Identity Replicas in WSNabstractWireless sensor networks (WSN) are often deployed in hostile environments, where an attacker can also capture some nodes. Once a node is captured, the attacker can re-program it and start replicating the node. These replicas can then be deployed in all (or a part of) the network area. The replicas can thus perform the attack they are programmed for: DoS (Denial of Service), or influencing any voting mechanism are just examples. Detection of node replication attack is therefore a fundamental property of all the WSN applications in which an attacker presence is possible. The contribution of this paper is twofold: First, we analyze the desirable properties of a distributed mechanism for the detection of replicated IDs; second, we show that the first proposal recently appeared in literature to realize a distributed solution for the detection of replicas does not completely fulfil the requirements. Hence, the design of efficient and distributed protocols to detect node identity replicas is still an open and demanding issue. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
SMC | 2 |
| 2006 | Energy efficient node-to-node authentication and communication confidentiality in wireless sensor networks
Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
Wirel. Networks | 1 |
| 2005 | Computation, Memory and Bandwidth Efficient Distillation Codes to Mitigate DoS in MulticastabstractIn this paper we address the problem of Denial of Service (DoS) mitigation in multicast environment. The contribution of the paper is twofold: first, we introduce an optimization (PMT) on the Merkle tree distillation codes by leveraging the implicit redundancy of a Merkle tree representation. Second, we devise a new algorithm(CECInA) for encoding/decoding that mitigates DoS attacks on the end user device and reduces the buffer size in case of DoS. In particular, according to the type of DoS attack, CECInA achieves either complexity or buffering savings. This attack mitigation capability is not a feature offered by state of the art algorithms. Furthermore CECInA is particularly efficient when used in conjunction with PMT. We derive and plot analytical results that indicates that the proposed solutions are effective. Hence, CECInA can be a viable solution to mitigate DoS in multicast, particularly suited for contexts in which end-user devices are resource constrained. As for PMT, note that it is a general technique that can be adopted independently from CECInA. Roberto Di Pietro, Stefano Chessa, Piero Maestrini |
SecureComm | 1 |
| 2005 | Short Paper: Practically Unbounded One-Way Chains for Authentication with Backward SecrecyabstractOne-way hash chains have been the preferred choice (over symmetric and asymmetric key cryptography) in security setups where efficiency mattered; despite the ephemeral confidentiality and authentication they assure. They only support forward secrecy and have limitations over the chain size (bounded). In this paper, we show how the use of chameleon functions leads to the generation of practically unbounded one-way chains with constant memory storage requirement, providing forward, and backward secrecy as well. Such a cryptographic tool appears to be a great enabler for a variety of applications that could not be efficiently realized earlier. From our experiments we observed that this new kind of one-way chain formation adds a slight computational burden, which is justifiable by the unique advantages provided under our construction. The basic unit of our construction, chameleon function, can be elegantly used to design trees or even simpler star-like constructs Roberto Di Pietro, Antonio Durante, Luigi V. Mancini, Vishwas Patil |
SecureComm | 1 |
| 2004 | Efficient and Resilient Key Discovery Based on Pseudo-Random Key Pre-DeploymentabstractSummary form only given. A distributed wireless sensor network (WSN) is a collection of n sensors with limited hardware resources and multihop message exchange capabilities. Due to the scarceness of resources, the distributed paradigm required, and the threats to the security, a challenging problem is how to implement secure pair-wise communications among any pair of sensors in a WSN. In particular, storage memory and energy saving as well as resilience to physical compromising of a sensor are the more stringent requirements. The contributions are twofold: (1) we describe a new threat model to communications confidentiality in WSNs (the smart attacker model); under this new, more realistic threat model, the security features of the previous schemes proposed in the literature drastically decrease; (2) we provide a new pseudo-random key predeployment strategy that assures: (a) a key discovery phase that requires no communications; (b) high resilience against the smart attacker model. We provide both analytical evaluations and extensive simulations of the proposed scheme. The results indicate that our pseudo-random key predeployment proposal achieves a provably efficient assignment of keys to sensors, an energy preserving key discovery phase, and is resilient against the smart attacker model. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
IPDPS | 1 |
| 2004 | Key management for high bandwidth secure multicastabstractThis paper brings up a new concern regarding efficient re-keying of large groups with dynamic membership: minimizing the overall time it takes for the key server and the group members to process the re-keying message. Specifically, we concentrate on re-keying algorithms based on the Logical Key Hierarchy (LKH), and minimize the longest sequence of encryptions and decryptions that need to be done in a re-keying operation. We first prove a lower bound on the time required to perform a re-keying operation in this model, then we provide an optimal schedule of re-keying messages matching the above lower bound. In particular, we show that the optimal schedule can be found only when the ariety of the LKH key graph is chosen according to the available communication bandwidth and the users processing power. Our results show that key trees of ariety 3, commonly assumed to be optimal, are not optimal when used in high bandwidth networks, or networks of devices with low computational power like sensor networks. Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
J. Comput. Secur. | 1 |
| 2003 | A Time Driven Methodology for Key Dimensioning in Multicast Communications
Roberto Di Pietro, Luigi V. Mancini, Alessandro Mei |
SEC | 1 |
| 2003 | A Reliable Key Authentication Schema for Secure Multicast CommunicationsabstractThe paper analyzes the Logical Key Hierarchy (LKH) secure multicast protocol focusing on the reliability of the re-keying authentication process. We show that the key management in the LKH model is subject to some attacks. In particular, these attacks can be performed by entities external to the multicast group, as well as from internal users of the multicast group. The spectrum of these attacks is spread from the denial of service (DoS) to the session hijack that is the attacker is able to have legitimate users to commit on a session key that is provided by the attacker. The contributions of this paper are: (1) the definition of the threats the LKH key management is subject to; and (2) a reliable key authentication scheme that solves the weaknesses previously identified. This objective is achieved without resorting to public key signatures. Roberto Di Pietro, Antonio Durante, Luigi V. Mancini |
SRDS | 1 |
| 2003 | Providing secrecy in key management protocols for large wireless sensors networks
Roberto Di Pietro, Luigi V. Mancini, Sushil Jajodia |
Ad Hoc Networks | 1 |
| 2002 | Secure Selective Exclusion in Ad Hoc Wireless Network
Roberto Di Pietro, Luigi V. Mancini, Sushil Jajodia |
SEC | 1 |