VLDB 2026 Research / reviewers in the wild / expert
Angelo Spognardi
dblp:82/6334
· DBLP profile ↗
29ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-6935-0701ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 3 since 2021Computer networks · 5 · 1 since 2021Artificial intelligence and machine learning · 4 · 1 first-authorSystems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 3Human-computer interaction and ubiquitous computing · 3Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorTheory of computation · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EtherMark: A Novel Architecture for Mobile-Traffic Dataset Creation with Perfect Labeling
Giovanni Pimpinella, Angelo Spognardi |
WoWMoM | 2 |
| 2025 | Generalized Encrypted Traffic Classification Using Inter-flow Signals
Federica Bianchi, Edoardo Di Paolo, Angelo Spognardi |
ARES (1) | 3 |
| 2025 | Opening Pandora's Packet: Expose IPv6 Implementations Vulnerabilities Using Differential Fuzzing
Enrico Bassetti, Edoardo Di Paolo, Francesco Drago, Mauro Conti, Angelo Spognardi |
ACNS (1) | 5 |
| 2023 | A New Model for Testing IPv6 Fragment Handling
Edoardo Di Paolo, Enrico Bassetti, Angelo Spognardi |
ESORICS (2) | 3 |
| 2020 | Emergent properties, models, and laws of behavioral similarities within groups of twitter users
Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
Comput. Commun. | 4 |
| 2018 | Predicting Online Review Scores Across Reviewer Categories
Michela Fazzolari, Marinella Petrocchi, Angelo Spognardi |
IDEAL (1) | 3 |
| 2018 | Analysis and Evaluation of SafeDroid v2.0, a Framework for Detecting Malicious Android ApplicationsabstractAndroid smartphones have become a vital component of the daily routine of millions of people, running a plethora of applications available in the official and alternative marketplaces. Although there are many security mechanisms to scan and filter malicious applications, malware is still able to reach the devices of many end-users. In this paper, we introduce the SafeDroid v2.0 framework, that is a flexible, robust, and versatile open-source solution for statically analysing Android applications, based on machine learning techniques. The main goal of our work, besides the automated production of fully sufficient prediction and classification models in terms of maximum accuracy scores and minimum negative errors, is to offer an out-of-the-box framework that can be employed by the Android security researchers to efficiently experiment to find effective solutions: the SafeDroid v2.0 framework makes it possible to test many different combinations of machine learning classifiers, with a high degree of freedom and flexibility in the choice of features to consider, such as dataset balance and dataset selection. The framework also provides a server, for generating experiment reports, and an Android application, for the verification of the produced models in real-life scenarios. An extensive campaign of experiments is also presented to show how it is possible to efficiently find competitive solutions: the results of our experiments confirm that SafeDroid v2.0 can reach very good performances, even with highly unbalanced dataset inputs and always with a very limited overhead. Marios Argyriou, Nicola Dragoni, Angelo Spognardi |
Secur. Commun. Networks | 3 |
| 2018 | DDoS-Capable IoT Malwares: Comparative Analysis and Mirai InvestigationabstractThe Internet of Things (IoT) revolution has not only carried the astonishing promise to interconnect a whole generation of traditionally “dumb” devices, but also brought to the Internet the menace of billions of badly protected and easily hackable objects. Not surprisingly, this sudden flooding of fresh and insecure devices fueled older threats, such as Distributed Denial of Service (DDoS) attacks. In this paper, we first propose an updated and comprehensive taxonomy of DDoS attacks, together with a number of examples on how this classification maps to real-world attacks. Then, we outline the current situation of DDoS-enabled malwares in IoT networks, highlighting how recent data support our concerns about the growing in popularity of these malwares. Finally, we give a detailed analysis of the general framework and the operating principles of Mirai, the most disruptive DDoS-capable IoT malware seen so far. Michele De Donno, Nicola Dragoni, Alberto Giaretta 0001, Angelo Spognardi |
Secur. Commun. Networks | 4 |
| 2018 | Social Fingerprinting: Detection of Spambot Groups Through DNA-Inspired Behavioral ModelingabstractSpambot detection in online social networks is a long-lasting challenge involving the study and design of detection techniques capable of efficiently identifying ever-evolving spammers. Recently, a new wave ofsocial spambotshas emerged, with advanced human-like characteristics that allow them to go undetected even by current state-of-the-art algorithms. In this paper, we show that efficient spambots detection can be achieved via an in-depth analysis of their collective behaviors exploiting thedigital DNAtechnique for modeling the behaviors of social network users. Inspired by its biological counterpart, in the digital DNA representation the behavioral lifetime of a digital account is encoded in a sequence of characters. Then, we define a similarity measure for such digital DNA sequences. We build upon digital DNA and the similarity between groups of users to characterize both genuine accounts and spambots. Leveraging such a characterization, we design theSocial Fingerprintingtechnique, which is able to discriminate among spambots and genuine accounts in both a supervised and an unsupervised fashion. We also evaluate the effectiveness of Social Fingerprinting and we compare it with three state-of-the-art detection showing the superiority of our solution. Finally, among the peculiarities of our approach is the possibility to apply off-the-shelf DNA analysis techniques to study online users behaviors and to efficiently rely on a limited number of lightweight account characteristics. Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2017 | Exploiting Digital DNA for the Analysis of Similarities in Twitter BehavioursabstractRecently, DNA-inspired online behavioral modeling and analysis techniques have been proposed and successfully applied to a broad range of tasks. In this paper, we employ a DNA-inspired technique to investigate the fundamental laws that drive the occurrence of similarities among Twitter users. The achieved results are multifold. First, we demonstrate that, despite apparently showing little to no similarities, the online behaviors of Twitter users are far from being uniformly random. Then, we perform a set of simulations to benchmark different behavioral models and to identify the models that better resemble human behaviors in Twitter. Finally, we demonstrate that the number and the extent of behavioral similarities within a group of Twitter users obey a log-normal distribution. Our results shed light on the fundamental properties that drive behaviors of groups of Twitter users, through the lenses of DNA-inspired behavioral modeling techniques. Our datasets are publicly available to the scientific community to further explore analytics of online behaviors. Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
DSAA | 4 |
| 2017 | Analysis of DDoS-Capable IoT MalwaresabstractThe Internet of Things (IoT) revolution promises to make our lives easier by providing cheap and always connected smart embedded devices, which can interact on the Internet and create added values for human needs.But all that glitters is not gold.Indeed, the other side of the coin is that, from a security perspective, this IoT revolution represents a potential disaster.This plethora of IoT devices that flooded the market were very badly protected, thus an easy prey for several families of malwares that can enslave and incorporate them in very large botnets.This, eventually, brought back to the top Distributed Denial of Service (DDoS) attacks, making them more powerful and easier to achieve than ever.This paper aims at provide an up-to-date picture of DDoS attacks in the specific subject of the IoT, studying how these attacks work and considering the most common families in the IoT context, in terms of their nature and evolution through the years.It also explores the additional offensive capabilities that this arsenal of IoT malwares has available, to mine the security of Internet users and systems.We think that this up-to-date picture will be a valuable reference to the scientific community in order to take a first crucial step to tackle this urgent security issue. Angelo Spognardi, Michele De Donno, Nicola Dragoni, Alberto Giaretta 0001 |
FedCSIS | 1 |
| 2016 | A Matter of Words: NLP for Quality Evaluation of Wikipedia Medical Articles
Vittoria Cozza, Marinella Petrocchi, Angelo Spognardi |
ICWE | 3 |
| 2016 | Bioinspired Security Analysis of Wireless Protocols
Marinella Petrocchi, Angelo Spognardi, Paolo Santi |
Mob. Networks Appl. | 2 |
| 2015 | Twitlang(er): Interactions Modeling Language (and Interpreter) for Twitter
Rocco De Nicola, Alessandro Maggi, Marinella Petrocchi, Angelo Spognardi, Francesco Tiezzi 0001 |
SEFM | 4 |
| 2015 | VISIO: A Visual Approach for Singularity Detection in Recommendation Systems
Alessandro Colantonio, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi |
TrustBus | 4 |
| 2015 | Fame for sale: Efficient detection of fake Twitter followersabstractFake followers are those Twitter accounts specifically created to inflate the number of followers of a target account. Fake followers are dangerous for the social platform and beyond, since they may alter concepts like popularity and influence in the Twittersphere—hence impacting on economy, politics, and society. In this paper, we contribute along different dimensions. First, we review some of the most relevant existing features and rules (proposed by Academia and Media) for anomalous Twitter accounts detection. Second, we create a baseline dataset of verified human and fake follower accounts. Such baseline dataset is publicly available to the scientific community. Then, we exploit the baseline dataset to train a set of machine-learning classifiers built over the reviewed rules and features. Our results show that most of the rules proposed by Media provide unsatisfactory performance in revealing fake followers, while features proposed in the past by Academia for spam detection provide good results. Building on the most promising features, we revise the classifiers both in terms of reduction of overfitting and cost for gathering the data needed to compute the features. The final result is a novel Class A classifier, general enough to thwart overfitting, lightweight thanks to the usage of the less costly features, and still able to correctly classify more than 95% of the accounts of the original training set. We ultimately perform an information fusion-based sensitivity analysis, to assess the global sensitivity of each of the features employed by the classifier. The findings reported in this paper, other than being supported by a thorough experimental methodology and interesting on their own, also pave the way for further investigation on the novel issue of fake Twitter followers. Stefano Cresci, Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi, Maurizio Tesconi |
Decis. Support Syst. | 4 |
| 2014 | Maturity Assessment of Wikipedia Medical ArticlesabstractRecent studies report that Internet users are growingly looking for health information through the Wikipedia Medicine Portal, a collaboratively edited multitude of articles with contents often comparable with professionally edited material. Automatic quality assessment of the Wikipedia medical articles has not received much attention by Academia and it presents open distinctive challenges. In this paper, we propose to tag the medical articles on the Wikipedia Medicine Portal, clearly stating their maturity degree, intended as a summarizing measure of several article properties. For this purpose, we adopt the Analytic Hierarchy Process, a well known methodology for decision making, and we evaluate the maturity degree of more than 24000 Wikipedia medical articles. The obtained results show how the qualitative analysis of medical content not always overlap with a quantitative analysis (an example of which is shown in the paper), since important properties of an article can hardly be synthesized by quantitative features. This seems particularly true when the analysis considers the concept of maturity, defined and verified in this work. Riccardo Conti, Emanuel Marzini, Angelo Spognardi, Ilaria Matteucci, Paolo Mori, Marinella Petrocchi |
CBMS | 3 |
| 2014 | No NAT'd User Left Behind: Fingerprinting Users behind NAT from NetFlow Records AloneabstractIt is generally recognized that the network traffic generated by an individual acts as his biometric signature. Several tools exploit this fact to fingerprint and monitor users. Often, though, these tools access the entire traffic, including IP addresses and payloads. In general, this is not feasible on the grounds that both performance and privacy would be negatively affected. In reality, most ISPs convert user traffic into Net Flow records for a concise representation that does not include the payload. More importantly, a single IP address belonging to a large and distributed network is usually masked using Network Address Translation techniques, thus a few IP addresses may be associated to thousands of individuals (NAT'd IPs). We devised a new fingerprinting framework that overcomes these hurdles. Our system is able to analyze a huge amount of network traffic represented as Net Flows, with the intent to track people. It does so by accurately inferring when users are connected to the network and which IP addresses they are using, even though thousands of users are hidden behind NAT. Our prototype implementation was deployed and tested within an existing large metropolitan WiFi network serving about 200,000 users, with an average load of more than 1,000 users simultaneously connected behind 2 NAT'd IP addresses only. Our solution turned out to be very effective, with an accuracy greater than 90%. We also devised new tools and refined existing ones that may be applied to other contexts related to Net Flow analysis. Nino Vincenzo Verde, Giuseppe Ateniese, Emanuele Gabrielli, Luigi V. Mancini, Angelo Spognardi |
ICDCS | 5 |
| 2014 | A Lot of Slots - Outliers Confinement in Review-Based Systems
Roberto Di Pietro, Marinella Petrocchi, Angelo Spognardi |
WISE (1) | 3 |
| 2014 | Clone wars: Distributed detection of clone attacks in mobile WSNs
Mauro Conti, Roberto Di Pietro, Angelo Spognardi |
J. Comput. Syst. Sci. | 3 |
| 2012 | Relieve Internet Routing Security of Public Key InfrastructureabstractLack of security mechanisms expose the Border Gateway Protocol (BGP) to a wide range of threats that are constantly undermining security of the Internet. Most prominent attacks include prefix hijacking and announcement of false routes to maliciously attract or divert traffic. A number of cryptographic solutions to prevent both attacks have been proposed but have not been adopted due to involved operations and considerable overhead. Most of them rely on digital signatures to authorize Autonomous Systems to propagate route announcements. Surprisingly, the scientific community has devoted only little interest to the problem of revocation in BGP. In particular, BGP systems based on Public Key Infrastructure allow to revoke an Autonomous System by revoking its public key certificate. However, there seem to be no solution for selective revocation of AS-path announcements. This paper introduces reBGP, an enhanced version of BGP that leverages Identity Based Cryptography to secure BGP with minimal overhead. reBGP prevents prefix hijacking and false route announcement through Aggregate Identity Based Signatures and provides an effective revocation means to invalidate AS-path announcements. reBGP enjoys a constant overhead to verify authenticity of routes and does not require a Public Key Infrastructure. Extensive testing of our implementation, show that our proposal represents a practical solution to secure BGP. Luigi V. Mancini, Angelo Spognardi, Claudio Soriente, Antonio Villani, Domenico Vitali |
ICCCN | 2 |
| 2012 | DDoS Detection with Information Theory Metrics and Netflows - A Real Case
Domenico Vitali, Antonio Villani, Angelo Spognardi, Roberto Battistoni, Luigi V. Mancini |
SECRYPT | 3 |
| 2011 | Intrusion-resilient integrity in data-centric unattended WSNs
Roberto Di Pietro, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
Pervasive Mob. Comput. | 3 |
| 2010 | eRIPP-FS: Enforcing privacy and security in RFIDabstractAbstract In RFID systems addressing security issues, many authentication techniques require the tag to keep some sort of synchronization with the reader. In particular, this is true in those proposals that leverage hash chains. When the reader and the tag get de‐synchronized, possibly by an attacker, this paves the way to several denial of service (DoS) attacks, as well as threatening privacy (e.g.,viathetiming attack). Even if de‐synchronization happens for non‐malicious causes, this event has a negative effect on performances (for instance, slowing down the authentication process). In this paper, we provide a solution to cope with the de‐synchronization between the tag and the reader when hash chains are employed. In particular, our solution relies on mutual reader‐tag authentication, achievedviahash traversal and Merkle tree techniques. We show that this techniques applied to an existing security protocol for RFID systems, such as RIPP‐FS, make timing attacks hard to succeed. Moreover, the proposed solutions can be transparently and independently adopted by similar security protocols as well to thwart timing attack and/or to provide reader‐tag mutual authentication. Finally, extensive simulations show that our proposal introduces a negligible overhead to recover de‐synchronization. Copyright © 2009 John Wiley & Sons, Ltd. Mauro Conti, Roberto Di Pietro, Luigi V. Mancini, Angelo Spognardi |
Secur. Commun. Networks | 4 |
| 2009 | Collaborative authentication in unattended WSNsabstractAn unattended wireless sensor network (UWSN) might collect valuable data representing an attractive target for the adversary. Since a sink visits the network infrequently, unattended sensors cannot immediately off-load data to some safe external entity. With sufficient time between sink visits, a powerful mobile adversary can easily compromise sensor-collected data. Roberto Di Pietro, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
WISEC | 3 |
| 2009 | Playing hide-and-seek with a focused mobile adversary in unattended wireless sensor networks
Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
Ad Hoc Networks | 4 |
| 2009 | Data Security in Unattended Wireless Sensor NetworksabstractIn recent years, wireless sensor networks (WSNs) have been a very popular research topic, offering a treasure trove of systems, networking, hardware, security, and application-related problems. Much of prior research assumes that the WSN is supervised by a constantly present sink and sensors can quickly offload collected data. In this paper, we focus on unattended WSNs (UWSNs) characterized by intermittent sink presence and operation in hostile settings. Potentially lengthy intervals of sink absence offer greatly increased opportunities for attacks resulting in erasure, modification, or disclosure of sensor-collected data. This paper presents an in-depth investigation of security problems unique to UWSNs (including a new adversarial model) and proposes some simple and effective countermeasures for a certain class of attacks. Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
IEEE Trans. Computers | 4 |
| 2008 | Catch Me (If You Can): Data Survival in Unattended Sensor NetworksabstractUnattended sensor networks operating in hostile environments might collect data that represents a high-value target for the adversary. The unattended sensor's inability to off-load - in real time - sensitive data to a safe external entity makes it easy for the adversary to mount a focused attack aimed at eliminating certain target data. In order to facilitate survival of this data, sensors can collectively attempt to confuse the adversary by changing its location and content, i.e., by periodically moving the data around the network and encrypting it. In this paper, we focus on data survival in unattended sensor networks faced with an adversary intent on surgically destroying data which it considers to be of high value. After motivating the problem and considering several attack flavors, we propose several simple techniques and provide their detailed evaluation. Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik |
PerCom | 4 |
| 2006 | A formal framework for the performance analysis of P2P networks protocolsabstractIn this paper, we propose a formal framework based on the Markov chains to prove the performance of P2P protocols. Despite the proposal of several protocols for P2P networks, sometimes there is a lack of a formal demonstration of their performance: experimental simulations are the most used method to evaluate their performance, such as the average length of a lookup. In this paper, we introduce a versatile model for the analysis of P2P protocols. We employ this model to formally prove which is the average lookup length for two sample protocols: BaRT and Koorde. We verify the effectiveness of the proposed framework also via extensive simulations. Angelo Spognardi, Roberto Di Pietro |
IPDPS | 1 |