VLDB 2026 Research / reviewers in the wild / expert
Cataldo Basile
dblp:82/1816
· DBLP profile ↗
31ranked-venue papers
15as first author
10since 2021 · last 2026
0000-0002-8016-1490ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 15 · 4 first-author · 6 since 2021Security and privacy · 6 · 2 first-author · 3 since 2021Computer networks · 5 · 4 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Limitations of Large Language Models for Cybersecurity Risk Assessment
Monica Chingate, Gabriele Gatti, Cataldo Basile |
COMPSAC | 3 |
| 2026 | From Threat Intelligence to Firewall Rules: Semantic Relations in Hybrid AI Agent and Expert System Architectures
Chiara Bonfanti, Davide Colaiacomo, Luca Cagliero, Cataldo Basile |
ICWE | 4 |
| 2026 | Automatic selection of protections to mitigate risks against software applicationsabstractThis paper introduces a novel approach for the automated selection of software protections to mitigate Machine-At-The-End risks against critical assets within software applications. We formalize the key elements involved in protection decision-making — including code artifacts, assets, security requirements, attacks, and software protections — and frame the protection process through a model inspired by game theory. In this model, a defender strategically applies protections to various code artifacts of a target application, anticipating repeated attack attempts by adversaries against the confidentiality and integrity of the application’s assets. The selection of the optimal defense maximizes resistance to attacks while ensuring the application remains usable by constraining the overhead introduced by protections. The game is solved through a heuristic based on a mini-max depth-first exploration strategy, augmented with dynamic programming optimizations for improved efficiency. Central to our formulation is the introduction of the Software Protection Index, an original contribution that extends existing notions of potency and resilience by evaluating protection effectiveness against attack paths using software metrics and expert assessments. We validate our approach through a proof-of-concept implementation and expert evaluations, demonstrating that automated software protection is a practical and effective solution for risk mitigation in software. Daniele Canavese, Leonardo Regano, Cataldo Basile, Bjorn De Sutter |
Comput. Secur. | 3 |
| 2026 | Empirical assessment of the code comprehension effort needed to attack programs protected with obfuscationabstractEvaluating the effectiveness of software protection is crucial for selecting the most effective methods to safeguard assets within software applications. Obfuscation involves techniques that deliberately modify software to make it more challenging to understand and reverse-engineer, while maintaining its original functionality. Although obfuscation is widely adopted, its effectiveness remains largely unexplored and not rigorously evaluated. This paper presents a controlled experiment involving Master’s students performing code comprehension tasks on applications hardened with obfuscation. The experiment’s goals are to assess the effectiveness of obfuscation in delaying code comprehension by attackers and to determine whether complexity metrics can accurately predict the impact of these protections on success rates and durations of code comprehension tasks. The study is the first to evaluate the effect of layering multiple obfuscation techniques on a single piece of protected code. It also provides experimental evidence of the correlation between objective metrics of the attacked code and the likelihood of a successful attack, bridging the gap between objective and subjective approaches to estimating potency. Finally, the paper highlights significant aspects that warrant additional analysis and opens new avenues for further experiments. Leonardo Regano, Daniele Canavese, Cataldo Basile, Marco Torchiano |
Comput. Secur. | 3 |
| 2026 | A Formal Model of Security Controls' Capabilities and Its Applications to Policy Refinement and Incident ManagementabstractEnforcing security requirements in networked information systems relies on technical security controls to mitigate the risks posed by increasingly sophisticated threats. Configuring these controls is challenging; even nowadays, administrators must perform it without adequate tool support. Hence, this process is plagued by errors that result in insecure postures, security incidents, and a lack of promptness in addressing threats. This paper presents the Security Capability Model (SCM), a formal model that abstracts the features that security controls offer for enforcing security policies, which includes an Information Model that depicts the basic concepts related to rules (i.e., conditions, actions, events) and policies (i.e., conditions’ evaluation, resolution strategies, default actions), and a Data Model that covers the capabilities needed to describe different types of filtering and channel protection controls. Following state-of-the-art design patterns, the model enables the generation of abstract versions of the security controls’ languages and a model-driven approach for translating abstract policies into device-specific configuration settings. By validating its effectiveness in real-world scenarios, we demonstrate that SCM enables the automation of various and complex security tasks, including accurate and granular security control comparison, policy refinement, and incident response. Lastly, we present opportunities for extensions and integration with other frameworks and models. Cataldo Basile, Gabriele Gatti, Francesco Settanni |
IEEE Trans. Netw. | 1 |
| 2024 | A Threat Analysis of Cooperative Intelligent Transport Systems: C-Roads ScenariosabstractThe transition towards cooperative intelligent trans-port systems (C- ITS) requires coordinated efforts from all stakeholders. In this context, the European C- Roads project aims to deploy and harmonize C- ITS at a continental scale to facilitate interconnected and autonomous road networks, enabling efficient traffic management, improved road safety, and reduced emissions. This work provides a third-party point of view on the challenges posed by cyberattacks against these systems. It contextualizes and investigates threat models for C-Roads use cases, introducing key concepts, analyzing the inherent literature on threat modelling, and presenting application-specific scenarios. It discusses results and future directions, highlighting the importance of collaborative efforts from all the involved actors to shape the future of transportation. Gabriele Gatti, Marco Civera, Cataldo Basile, Massimiliano Masi, Michele La Manna |
COMPSAC | 3 |
| 2023 | An expert system for automatic cyber risk assessment and its AI-based improvementsabstractEvaluating risks against IT Systems is a complex yet crucial process that requires significant resources and competencies. This paper proposes RiskMan, an expert system for the automatic assessment of cyber risks that computes a risk score using information gathering and vulnerability assessment tools, public databases, and leaks from the dark web without involving cybersecurity experts. Moreover, RiskMan uses AI-driven techniques to determine risks also when only partial information is available. Gabriele Gatti, Cataldo Basile, Guido Perboli |
COMPSAC | 2 |
| 2023 | A Model for Automated Cybersecurity Threat Remediation and SharingabstractThis paper presents an approach to the automatic remediation of threats reported by Cyber Threat Intelligence. Remediation strategies, named Recipes, are expressed in a close-to-natural language for easy validation. Thanks to the developed models, they are interpreted, contextualized, and then translated into CACAO Security playbooks, a standard format ready for automatic enforcement, without human intervention. The presented approach also allows sharing of remediation procedures on threat-sharing platforms (e.g. MISP) which improves the overall security posture. The effectiveness of the approach has been tested in the context of two EC-funded projects. Francesco Settanni, Leonardo Regano, Cataldo Basile, Antonio Lioy |
NetSoft | 3 |
| 2023 | Design, implementation, and automation of a risk management approach for man-at-the-End software protectionabstractThe last years have seen an increase in Man-at-the-End (MATE) attacks against software applications, both in number and severity. However, software protection, which aims at mitigating MATE attacks, is dominated by fuzzy concepts and security-through-obscurity. This paper presents a rationale for adopting and standardizing the protection of software as a risk management process according to the NIST SP800-39 approach. We examine the relevant constructs, models, and methods needed for formalizing and automating the activities in this process in the context of MATE software protection. We highlight the open issues that the research community still has to address. We discuss the benefits that such an approach can bring to all stakeholders. In addition, we present a Proof of Concept (PoC) decision support system that instantiates many of the discussed construct, models, and methods and automates many activities in the risk analysis methodology for the protection of software. Despite being a prototype, the PoC’s validation with industry experts indicated that several aspects of the proposed risk management process can already be formalized and automated with our existing toolbox and that it can actually assist decision making in industrially relevant settings. Cataldo Basile, Bjorn De Sutter, Daniele Canavese, Leonardo Regano, Bart Coppens 0001 |
Comput. Secur. | 1 |
| 2022 | A model of capabilities of Network Security FunctionsabstractThis paper presents a formal model of the features, named security capabilities, offered by the controls used for enforcing security policies in computer networks. It has been designed to support policy refinement and policy translation and address useful, practical tasks in a vendor-independent manner. The model adopts state-of-the-art design patterns and has been designed to be extensible. The model describes the actions that the controls can perform (e.g. deny packets or encrypt flows), the conditions to select on what to apply the actions, how to compose valid configuration rules from them, and how to build configurations from rules. It proved effective to model filtering controls and iptables. Cataldo Basile, Daniele Canavese, Leonardo Regano, Ignazio Pedone, Antonio Lioy |
NetSoft | 1 |
| 2020 | Empirical assessment of the effort needed to attack programs protected with client/server code splitting
Alessio Viticchié, Leonardo Regano, Cataldo Basile, Marco Torchiano, Mariano Ceccato, Paolo Tonella |
Empir. Softw. Eng. | 3 |
| 2019 | Understanding the behaviour of hackers while performing attack tasks in a professional setting and in a public challenge
Mariano Ceccato, Paolo Tonella, Cataldo Basile, Paolo Falcarin, Marco Torchiano, Bart Coppens 0001, Bjorn De Sutter |
Empir. Softw. Eng. | 3 |
| 2019 | A meta-model for software protections and reverse engineering attacks
Cataldo Basile, Daniele Canavese, Leonardo Regano, Paolo Falcarin, Bjorn De Sutter |
J. Syst. Softw. | 1 |
| 2019 | Adding Support for Automatic Enforcement of Security Policies in NFV NetworksabstractThis paper introduces an approach toward the automatic enforcement of security policies in network functions virtualization (NFV) networks and dynamic adaptation to network changes. The approach relies on a refinement model that allows the dynamic transformation of high-level security requirements into configuration settings for the network security functions (NSFs), and optimization models that allow the optimal selection of the NSFs to use. These models are built on a formalization of the NSF capabilities, which serves to unequivocally describe what NSFs are able to do for security policy enforcement purposes. The approach proposed is the first step toward a security policy aware NFV management, orchestration, and resource allocation system-a paradigm shift for the management of virtualized networks-and it requires minor changes to the current NFV architecture. We prove that our approach is feasible, as it has been implemented by extending the OpenMANO framework and validated on several network scenarios. Furthermore, we prove with performance tests that policy refinement scales well enough to support current and future virtualized networks. Cataldo Basile, Fulvio Valenza, Antonio Lioy, Diego R. López, Antonio Pastor 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2017 | Remotely Assessing Integrity of Software Applications by Monitoring Invariants: Present Limitations and Future Directions
Alessio Viticchié, Cataldo Basile, Antonio Lioy |
CRiSIS | 2 |
| 2017 | How professional hackers understand protected code while performing attack tasksabstractCode protections aim at blocking (or at least delaying) reverse engineering and tampering attacks to critical assets within programs. Knowing the way hackers understand protected code and perform attacks is important to achieve a stronger protection of the software assets, based on realistic assumptions about the hackers' behaviour. However, building such knowledge is difficult because hackers can hardly be involved in controlled experiments and empirical studies. The FP7 European project Aspire has given the authors of this paper the unique opportunity to have access to the professional penetration testers employed by the three industrial partners. In particular, we have been able to perform a qualitative analysis of three reports of professional penetration test performed on protected industrial code. Our qualitative analysis of the reports consists of open coding, carried out by 7 annotators and resulting in 459 annotations, followed by concept extraction and model inference. We identified the main activities: understanding, building attack, choosing and customizing tools, and working around or defeating protections. We built a model of how such activities take place. We used such models to identify a set of research directions for the creation of stronger code protections. Mariano Ceccato, Paolo Tonella, Cataldo Basile, Bart Coppens 0001, Bjorn De Sutter, Paolo Falcarin, Marco Torchiano |
ICPC | 3 |
| 2017 | Towards Optimally Hiding Protected Assets in Software ApplicationsabstractSoftware applications contain valuable assets that, if compromised, can make the security of users at stake and cause huge monetary losses for software developers. Software protections are applied whenever assets' security is at risk as they delay successful attacks. Unfortunately, protections might have recognizable fingerprints that can expose the location of the assets, thus facilitating the attackers' job. This paper presents a novel approach that uses three main methods to hide the protected assets: protection fingerprint replication, enlargement, and shadowing. The best way to hide assets is determined with a Mixed Integer Linear Program, which is automatically built starting from the code structure, the protected assets, and a model that depicts the dependencies among protection and the fingerprints they generate. Additional constraints, such as overhead limits are also supported to ensure the usability of the protected applications. Our implementation, which uses off-the-shelf solvers, showed promising performance and scalability on large applications. Leonardo Regano, Daniele Canavese, Cataldo Basile, Antonio Lioy |
QRS | 3 |
| 2017 | Classification and Analysis of Communication Protection Policy AnomaliesabstractThis paper presents a classification of the anomalies that can appear when designing or implementing communication protection policies. Together with the already known intra- and inter-policy anomaly types, we introduce a novel category, the inter-technology anomalies, related to security controls implementing different technologies, both within the same network node and among different network nodes. Through an empirical assessment, we prove the practical significance of detecting this new anomaly class. Furthermore, this paper introduces a formal model, based on first-order logic rules that analyses the network topology and the security controls at each node to identify the detected anomalies and suggest the strategies to resolve them. This formal model has manageable computational complexity and its implementation has shown excellent performance and good scalability. Fulvio Valenza, Cataldo Basile, Daniele Canavese, Antonio Lioy |
IEEE/ACM Trans. Netw. | 2 |
| 2016 | Assessment of Source Code Obfuscation TechniquesabstractObfuscation techniques are a general category of software protections widely adopted to prevent malicious tampering of the code by making applications more difficult to understand and thus harder to modify. Obfuscation techniques are divided in code and data obfuscation, depending on the protected asset. While preliminary empirical studies have been conducted to determine the impact of code obfuscation, our work aims at assessing the effectiveness and efficiency in preventing attacks of a specific data obfuscation technique - VarMerge. We conducted an experiment with student participants performing two attack tasks on clear and obfuscated versions of two applications written in C. The experiment showed a significant effect of data obfuscation on both the time required to complete and the successful attack efficiency. An application with VarMerge reduces by six times the number of successful attacks per unit of time. This outcome provides a practical clue that can be used when applying software protections based on data obfuscation. Alessio Viticchié, Leonardo Regano, Marco Torchiano, Cataldo Basile, Mariano Ceccato, Paolo Tonella, Roberto Tiella |
SCAM | 4 |
| 2016 | A Reference Architecture for Software ProtectionabstractThis paper describes the ASPIRE reference architecture designed to tackle one major problem in this domain: the lack of a clear process and an open software architecture for the composition and deployment of multiple software protections on software applications. Bjorn De Sutter, Paolo Falcarin, Brecht Wyseur, Cataldo Basile, Mariano Ceccato, Jérôme d'Annoville, Michael Zunke |
WICSA | 4 |
| 2016 | Towards Automatic Risk Analysis and Mitigation of Software Applications
Leonardo Regano, Daniele Canavese, Cataldo Basile, Alessio Viticchié, Antonio Lioy |
WISTP | 3 |
| 2015 | A novel approach for integrating security policy enforcement with dynamic network virtualizationabstractNetwork function virtualization (NFV) is a new networking paradigm that virtualizes single network functions. NFV introduces several advantages compared to classical approaches, such as the dynamic provisioning of functionality or the implementation of scalable and reliable services (e.g., adding a new instance to support demands). NFV also allows the deployment of security controls, like firewalls or VPN gateways, as virtualized network functions. However, currently there is not an automatic way to select the security functions to enable and to configure the selected ones according to a set of user's security requirements. This paper presents a first approach towards the integration of network and security policy management into the NFV framework. By adding to the NFV architecture a new software component, the Policy Manager, we provide NFV with an easy and effective way for users to specify their security requirements and a process that hides all the details of the correct deployment and configuration of security functions. To perform its tasks, the Policy Manager uses policy refinement techniques. Cataldo Basile, Antonio Lioy, Christian Pitscheider, Fulvio Valenza, Marco Vallini |
NetSoft | 1 |
| 2015 | A Formal Model of Policy ReconciliationabstractThis paper proposes a novel approach to perform the reconciliation of security policies by means of user-defined reconciliation strategies. The proposed policy reconciliation model allows several degree of freedom when specifying reconciliation strategies, which can be based not only on rule actions, like most of the works in literature, but also on other rule data (e.g., the conditions) and other external data (e.g., rule priorities, policy priorities). Additionally, it can be applied to reconcile policies at runtime and off-line, that is, it allows the generation of a reconciled policy. Moreover, the reconciliation process generates a detailed report on all the decision taken. Given its expressiveness, the approach can be also applied to simplify the policy specification process. The model has been validated against a practical example, the definition of the application layer filtering policy in a corporate scenario, and its performance has been tested with synthetic policies. Both validation and performance analysis gave encouraging results. Cataldo Basile, Antonio Lioy, Christian Pitscheider, Shilong Zhao |
PDP | 1 |
| 2015 | Analysis of Application-Layer Filtering Policies With Application to HTTPabstractApplication firewalls are increasingly used to inspect upper-layer protocols (as HTTP) that are the target or vehicle of several attacks and are not properly addressed by network firewalls. Like other security controls, application firewalls need to be carefully configured, as errors have a significant impact on service security and availability. However, currently no technique is available to analyze their configuration for correctness and consistency. This paper extends a previous model for analysis of packet filters to the policy anomaly analysis in application firewalls. Both rule-pair and multirule anomalies are detected, hence reducing the likelihood of conflicting and suboptimal configurations. The expressiveness of this model has been successfully tested against the features of Squid, a popular Web caching proxy offering various access control capabilities. The tool implementing this model has been tested on various scenarios and exhibits good performance. Cataldo Basile, Antonio Lioy |
IEEE/ACM Trans. Netw. | 1 |
| 2014 | Inter-technology Conflict Analysis for Communication Protection Policies
Cataldo Basile, Daniele Canavese, Antonio Lioy, Fulvio Valenza |
CRiSIS | 1 |
| 2013 | Towards a unified software attack model to assess software protectionsabstractAttackers can tamper with programs to break usage conditions. Different software protection techniques have been proposed to limit the possibility of tampering. Some of them just limit the possibility to understand the (binary) code, others react more actively when a change attempt is detected. However, the validation of the software protection techniques has been always conducted without taking into consideration a unified process adopted by attackers to tamper with programs. In this paper we present an extension of the mini-cycle of change, initially proposed to model the process of changing program for maintenance, to describe the process faced by an attacker to defeat software protections. This paper also shows how this new model should support a developer when considering what are the most appropriate protections to deploy. Cataldo Basile, Mariano Ceccato |
ICPC | 1 |
| 2013 | Improved Reachability Analysis for Security ManagementabstractNetwork reachability analysis evaluates the actual connectivity of an IT infrastructure. It can be performed by active network probing or examining a formal model of a target IT infrastructure. The latter approach is preferable as it does not interfere with the normal network behaviour and can be easily used during development and change management phases. In this paper we propose a novel modelling approach based on a geometric representation of device configurations (i.e. the policies) which allows the computation of the reachability analysis using the concept of equivalent firewall. An equivalent firewall is a fictitious device, ideally connected directly to the communication endpoints, that summarizes the network behaviour between them. Our model supports routing, filtering and address translation devices in a computationally effective way. In fact, the experimental results show that the computation of equivalent firewalls is performed in a negligible time and that then the reachability queries are answered in few seconds. Cataldo Basile, Daniele Canavese, Antonio Lioy, Christian Pitscheider |
PDP | 1 |
| 2012 | Network-Level Access Control Policy Analysis and TransformationabstractNetwork-level access control policies are often specified by various people (network, application, and security administrators), and this may result in conflicts or suboptimal policies. We have defined a new formal model for policy representation that is independent of the actual enforcement elements, along with a procedure that allows the easy identification and removal of inconsistencies and anomalies. Additionally, the policy can be translated to the model used by the target access control element to prepare it for actual deployment. In particular, we show that every policy can be translated into one that uses the “First Matching Rule” resolution strategy. Our policy model and optimization procedure have been implemented in a tool that experimentally demonstrates its applicability to real-life cases. Cataldo Basile, Alberto Cappadonia, Antonio Lioy |
IEEE/ACM Trans. Netw. | 1 |
| 2012 | FPGA-Based Remote-Code Integrity Verification of Programs in Distributed Embedded SystemsabstractThe explosive growth of networked embedded systems has made ubiquitous and pervasive computing a reality. However, there are still a number of new challenges to its widespread adoption that include scalability, availability, and, especially, security of software. Among the different challenges in software security, the problem of remote-code integrity verification is still waiting for efficient solutions. This paper proposes the use of reconfigurable computing to build a consistent architecture for generation of attestations (proofs) of code integrity for an executing program as well as to deliver them to the designated verification entity. Remote dynamic update of reconfigurable devices is also exploited to increase the complexity of mounting attacks in a real-word environment. The proposed solution perfectly fits embedded devices that are nowadays commonly equipped with reconfigurable hardware components that are exploited to solve different computational problems. Cataldo Basile, Stefano Di Carlo, Alberto Scionti |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2010 | Towards a Network-Independent Policy SpecificationabstractA very ambitious objective in the field of policy-based systems is the provision of an intuitive and transparent way for policy specification, refinement and enforcement. This is one of the key enabling technologies for a simplified security management of complex networked environments. Currently, security policies are enforced by configuring the end devices by means of low-level device-specific parameters manually derived from high level specifications. This process, defined as policy translation, is still performed without a holistic view of the overall security requirements. This paper presents the Network Contextualization Tool (NCTool), a software supporting administrators in performing network dependent activities when configuring security enabled devices. The tool provides a great advantage in the management of complex networks. In fact, it simplifies the network administration tasks and reduces effort and responsibilities for the administrators, thus decreasing the risk of mistaken configurations. Cataldo Basile, Antonio Lioy, Marco Vallini |
PDP | 1 |
| 2008 | Integrating Deployment Techniques with Monitoring: The Proactive Configuration Checker (PCC)abstractAssuring security in distributed systems is a complex issue, nowadays getting more and more sensitive, because important services are exposed using Internet. Moreover, new concepts must be considered by computer scientists: resilience, maintainability and availability. One of the first consequences of successful attacks or management errors is the modification of configurations. While tools already exist able to check whether configurations are correct and compliant, there is no integration of these techniques with policy specification and related deployment. In this paper, it is presented the Proactive Configuration Checker (PCC), a tool designed to test configurations for modification that takes advantage from an integrated approach, starting from policy specification to automatic deployment, in order to detect attacks, while reducing false positives. Cataldo Basile, Paolo Carlo Pomi, Piervito Scaglioso |
PDP | 1 |