Francesco Palmieri 0002

dblp:86/2508-2 · DBLP profile ↗
← Back
159ranked-venue papers
30as first author
46since 2021 · last 2026
0000-0003-1760-5527ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 44 · 9 first-author · 9 since 2021Computer networks · 24 · 9 first-author · 4 since 2021Security and privacy · 24 · 4 first-author · 9 since 2021Artificial intelligence and machine learning · 18 · 10 since 2021Databases, data management, data science and information retrieval · 17 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-authorTheory of computation · 1
YearPublicationVenuePosition
2026 On-device training and pruning for energy saving and continuous learning in resource-constrained MCUs
Pietro Fusco, Gennaro Pio Rimoli, Antonio Guerriero, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.4
2026 A lightweight blockchain-based defense method for federated self-supervised learning
Hadiseh Rezaei, Marjan Golmaryami, Hadis Rezaei, Francesco Palmieri 0002
Future Gener. Comput. Syst.4
2025 TinyML-Based Intrusion Detection System for Handling Class Imbalance in IoT-Edge Domain Using Siamese Neural Network on MCU
Pietro Fusco, Alberto Montefusco, Gennaro Pio Rimoli, Francesco Palmieri 0002, Massimo Ficco
AINA (3)4
2025 Cross-Model Federated Learning-Based Network Traffic Classification
Kainat Ibrar, Francesco Palmieri 0002, Pietro Fusco, Massimo Ficco
AINA (3)2
2025 Epidemic Analysis of the Propagation of Multiple Malware Infectious in Wireless Sensor Networks
Leila Moradi, Eslam Farsimadan, Gianni D'Angelo, Bruno Carpentieri, Francesco Palmieri 0002
AINA (8)5
2025 A Modular and Scalable Framework for Effective Server-Side Forensic Analysis of XSS Attacks
Raffaele Pizzolante, Arcangelo Castiglione, Michele Mastroianni, Francesco Palmieri 0002
AINA (4)4
2025 A Mobile Forensic Tool for Enhancing Cyber-Physical Security by Detecting XSS Attacks Through Web Server Access Log Analysis
Raffaele Pizzolante, Arcangelo Castiglione, Michele Mastroianni, Francesco Palmieri 0002
AINA (8)4
2025 CTAT: A Blockchain-Driven Conditional Traceable Access Token for Enhancing Performance and Security in the Supply Chain of Sensitive Pharmaceuticals
Hadis Rezaei, Massimo Ficco, Francesco Palmieri 0002
AINA (8)3
2025 Generative models with helical time encoding for seasonal time series forecasting
abstract
Many time series forecasting methods rely on sliding windows of historical data. The window size is one of the hyperparameters that significantly influences predictive accuracy, yet optimal selection remains challenging in practice. We propose an encoding of time that, when used with generative models, transforms the seasonal time series forecasting problem into a conditional generation problem on a helical representation. This representation allows models to learn position–value relationships rather than sequential dependencies, enabling forecasting using only time-derived conditions, thereby eliminating the need for sliding windows and recent observations during inference while fully exploiting historical patterns during training. We evaluated our approach using conditional Generative Adversarial Networks on taxi demand and influenza-like illness forecasting benchmarks. Our model demonstrated substantial improvements over state-of-the-art baselines in long-term forecasting scenarios. For influenza-like illness forecasting, we achieved a 42.2% mean absolute error reduction (from 1.1378 to 0.6582) and a 35.3% root mean square error reduction (from 1.3063 to 0.8453) compared to baseline models using only historical data for long-term predictions. For taxi demand forecasting, we achieved a 70.7% root mean square error reduction (from 0.7926 to 0.2322) compared to baseline models using recent observations during inference. Our approach provides a specialized solution for seasonal time series forecasting, presenting advantages when long-term predictions are required without waiting for new actual data or in high-frequency applications where continuous re-computation is expensive. • Helical time encoding makes seasonal patterns geometrically explicit in time series. • Paradigm shift from sequential forecasting to conditional generation. • No recent observations required for long-term forecasting. • Implementation of conditional Generative Adversarial Networks. • Edge-ready for real-time, high-frequency seasonal time series forecasting.
Lorenzo Porcelli, Ugo Fiore, Francesco Palmieri 0002
Eng. Appl. Artif. Intell.3
2025 Special Issue on integration of machine learning and edge computing for next generation of smart wearable systems
Paolo Gastaldo, Edoardo Ragusa, Strahinja Dosen, Francesco Palmieri 0002
Future Gener. Comput. Syst.4
2025 A distance-based network activity correlation framework for defeating anonymization overlays
abstract
As the effectiveness of modern Internet-based anonymization infrastructures grows, law enforcement agencies are experiencing a progressive erosion of their surveillance capabilities. This can severely undermine their efforts to prevent and investigate various types of unlawful activities, potentially increasing the impunity of organized criminal networks. Balancing the legitimate privacy needs of individuals with the imperative to maintain public safety and combat criminal behavior in the digital world remains a complex tradeoff for both policymakers and technologists who need to find a systematic and reliable way to link the traffic traces associated with criminal activities to their anonymized origins. Accordingly, this paper presents a simple but very effective de-anonymization approach capable of associating traffic traces captured at the edge of the overlay infrastructures, in correspondence with the true origins, to those captured in correspondence with the destinations. The approach is based on determining the minimum-distance pairs within a complete bipartite graph in which the traffic traces are the nodes. Experiments with different distance functions, applied in varied ways, show that the resulting framework appears to be a promising solution that is scalable and easily deployable on real-life network equipment. • A framework to de-anonymize traffic based on distances between descriptions of traffic. • An estimation of the confidence in results is provided. • The proposed solution is interpretable and it scales well.
Ugo Fiore, Francesco Palmieri 0002
Inf. Sci.2
2025 A privacy-preserving certificate-less aggregate signature scheme with detectable invalid signatures for VANETs
Xiaoliang Wang 0002, Guikai Liu, Kuanching Li, Biao Hu 0003, Francesco Palmieri 0002
J. Inf. Secur. Appl.7
2025 Context-aware coverage path planning for a swarm of UAVs using mobile ground stations for battery-swapping
abstract
Abstract The usage of swarms of drones is expected to continue growing in the next years, particularly in dangerous scenarios, such as monitoring and rescue missions in hostile and disaster areas. Small-sized Unmanned Aerial Vehicles (UAVs) are highly suitable for use in such scenarios due to their agility and maneuverability. On the other hand, their limited battery capacity poses significant challenges, especially during missions requiring full coverage of large areas in a short time and extreme weather conditions. This work proposed an energy efficiency approach, which makes use of mobile ground-based battery-swapping stations (BSSes), to speed up the UAV’s battery replacement and reduce energy waste in the round trip to the charging station. Specifically, a Context-Aware Coverage Path Planning (CACPP) problem has been formulated to determine the complete coverage path of a large area by a swarm of UAVs, minimizing the path overlapping and UAV battery swapping. The model takes into account the need to continue re-planning the mission, depending on the weather conditions (i.e., temperature and wind), the presence of obstacles, and the residual energy levels of the drones, as well as the relative positions of the drones and mobile BSSes. To solve the CACPP problem, an iterative approach leveraging two synchronized optimization models for planning UAV paths and BSS routes has been presented. As the CACPP problem is NP-hard, a heuristic procedure for solving it has also been evaluated. Experimental results show that it can be appropriate for large instances of the problem.
Lorenzo Porcelli, Massimo Ficco, Gianni D'Angelo, Francesco Palmieri 0002
Soft Comput.4
2025 Generalized Defensive Modeling of Fake News Propagation in Social Networks Using Fractional Differential Equations
abstract
The rapid progress of Internet technology has led to a strong increase in the use of online social networks for disseminating information on the Internet. In this scenario, it is crucial to establish approaches that can effectively reduce the diffusion of false information (fake news) that can potentially cause harm to society. A defensive approach, based on integer-order differential equations, has been recently developed to analyze the effects of verification and blocking of users for containing the spread of fake news. Starting from it, we introduce a novel fractional model providing a more accurate, powerful, and realistic representation of the transmission of fake news messages. The model aims to predict the spread of such messages, by better considering the effect of the system's status evolution over time. The use of fractional differential equations to schematize the propagation of fake news results in incorporating a greater amount of memory information and better considering hereditary properties of the system of interest, also capturing its hidden nonlinear dynamics, mainly related to fractality and multiscale nature.
Alfredo De Santis, Eslam Farsimadan, Leila Moradi, Francesco Palmieri 0002
IEEE Trans. Comput. Soc. Syst.4
2024 XSS-Unearth: A Tool for Forensics Analysis of XSS Attacks
Davide Alfieri, Massimo Ficco, Michele Mastroianni, Francesco Palmieri 0002
AINA (5)4
2024 Unlocking Insights: An Extensible Framework for Automated Metadata Extraction from Online Documents
abstract
Information Gathering is a fundamental stage in a typical Penetration Testing (PT) process, in which penetration testers collect as much information as possible regarding a target system to uncover vulnerabilities, threats, and security issues. Metadata extraction plays an important role in this stage since it can reveal significant details about the target system, such as used technologies, software versions, user information, and network data, which can expose potential attack vectors. This paper introduces a novel framework for automated metadata extraction from documents linked within a specified web page. The framework is designed to streamline Information Gathering processes by offering an easy-to-use, integrated, extensible, and flexible solution. Our proposal can be effective in uncovering information that is not immediately visible to a penetration tester, giving them a greater chance of success in identifying the most fruitful attack patterns.
Raffaele Pizzolante, Arcangelo Castiglione, Francesco Palmieri 0002
TrustCom3
2024 When explainability turns into a threat - using xAI to fool a fake news detection method
abstract
The inclusion of Explainability of Artificial Intelligence (xAI) has become a mandatory requirement for designing and implementing reliable, interpretable and ethical AI solutions in numerous domains. xAI is now the subject of extensive research, from both the technical and social science perspectives. It is being received enthusiastically by legislative bodies and regular users of machine-learning-boosted applications alike. However, opening the black box of AI comes at a cost. This paper presents the results of the first study proving that xAI can enable successful adversarial attacks in the domain of fake news detection and lead to a decrease in AI security. We postulate the novel concept that xAI and security should strike a balance, especially in critical applications, such as fake news detection. An attack scheme against fake news detection methods is presented that employs an explainable solution. The described experiment demonstrates that the well-established SHAP explainer can be used to reshape the structure of the original message in such a way that the value of the model's prediction could be arbitrarily forced, whilst the meaning of the message stays the same. The paper presents various examples for which the SHAP values are used to point the adversary to the words and phrases that have to be changed to flip the label on the model prediction. To the best of the authors' knowledge, it has been the first research work to experimentally demonstrate the sinister side of xAI. As the generation and spreading of fake news has become a tool of modern warfare and a grave threat to democracy, the potential impact of explainable AI should be addressed as soon as possible.
Rafal Kozik, Massimo Ficco, Aleksandra Pawlicka, Marek Pawlicki, Francesco Palmieri 0002, Michal Choras
Comput. Secur.5
2024 Estimating electricity consumption at city-level through advanced machine learning methods
abstract
An effective energy management system relies on the accurate prediction of electricity consumption, facilitating energy suppliers to optimise energy distribution, reduce energy waste, and avoid overloading the power system.This paper analyses different methods for the estimation of electricity consumption at the level of an urban area.A statistical model based on Trigonometric seasonality, Box-Cox transformation, Auto-Regressive Moving Average errors, Trend and Seasonal components is first presented.Then a model based on fuzzy logic is also proposed.These methods will be optimised and evaluated on a dataset collected by the electric power supply agency of Sibiu, Romania, with the goal of reducing the forecast error.The models are also compared with a Markov stochastic model and with a Long Short-Term Memory neural model.The experiments have shown that our statistical model using a history length of 200 electricity consumption values and a daily seasonality is the most efficient, with the lowest mean absolute error of 3.6 MWh, thus making it a good candidate for integration into a city-level energy management system.
Arpad Gellert, Lorena M. Olaru, Adrian Florea, Ileana-Ioana Cofaru, Ugo Fiore, Francesco Palmieri 0002
Connect. Sci.6
2024 Testing the Resilience of MEC-Based IoT Applications Against Resource Exhaustion Attacks
abstract
Multi-access Edge Computing (MEC) is an emerging computing model that provides the necessary on-demand resources and services to the edge of the network, ensuring powerful computing, storage capacity, mobility, location, and context awareness support to emerging Internet of Things (IoT) applications. Nonetheless, its complex hierarchical model introduces new architectural interdependencies, which can influence the resilience of IoT applications against cyber attacks. Although application resilience has been investigated in the context of cloud computing, existing studies are not directly applicable to such an extended edge-cloud paradigm. The use of different enabling technologies at the edge of the network, such as various wireless access technologies and virtualization, implies several threats and challenges that make the analysis and deployment of resilience mechanisms a technically challenging problem. In this article, we first present an overview of the threat model, describing the threats for the different layers of this paradigm. We then study the impact of resource-exhausting attacks – a particularly relevant class for this paradigm - on three different IoT applications exploiting the services offered by the MEC-based architecture. We adopt a testing-based methodology conceived to characterize the resilience of such applications under attack. A set of most important resilience-related indicators are also identified. The characterization's results are useful to support the analyst in planning proper protection means at individual architectural layers.
Roberto Pietrantuono, Massimo Ficco, Francesco Palmieri 0002
IEEE Trans. Dependable Secur. Comput.3
2024 Bounds and Protocols for Graph-Based Distributed Secret Sharing
abstract
Distributed Secret Sharing is a (multi) secret sharing model in which the shares are distributed over storage nodes of a network and each participant is able to reconstruct a specific secret by accessing a subset of the storage nodes. In this work, we provide new Distributed (multi) Secret Sharing Protocols for a specific class of access structures, namely those that can be described with a graph. The protocols improve on previous results allowing a faster encoding and decoding phase while maintaining optimal storage requirements. Moreover, our protocols can manage any kind of graph, while previous protocols have been designed only for complete graphs, and we provide a complete characterization of graph-based protocols. We also prove some tight bounds on the size of the information held in the storage nodes and communication complexity by using an information-theoretic approach. Finally, we also introduce a computationally secure technique for the general case that allows improvements in the size of the needed disk space if secrecy is computational, that is, if the scheme is robust against resource-bounded adversaries.
Roberto De Prisco, Alfredo De Santis, Francesco Palmieri 0002
IEEE Trans. Dependable Secur. Comput.3
2023 On Cyber Security Risk of Medical Devices
Antonio Scarfò, Michele Mastroianni, Francesco Palmieri 0002
HIS (3)3
2023 Identifying patterns in multiple biomarkers to diagnose diabetic foot using an explainable genetic programming-based approach
Gianni D'Angelo, David Della-Morte, Donatella Pastore, Giulia Donadel, Alessandro De Stefano, Francesco Palmieri 0002
Future Gener. Comput. Syst.6
2023 Privacy-preserving malware detection in Android-based IoT devices through federated Markov chains
abstract
The continuous emergence of new and sophisticated malware specifically targeting Android-based Internet of Things devices is causing significant security hazards and is consequently fostering the need for effective detection models and strategies able to work with these hardware-constrained devices. In addition, since such models are often trained on confidential application data, many involved subjects are reluctant to share their data for this purpose. Accordingly, several Federated Learning-based solutions are emerging, which rely on the capabilities of Machine Learning models in malware detection/classification without sharing user data. However, Federated Learning methods are often adversely affected by non-independent and identically distributed data in terms of both the required training time and classification results. Therefore, a promising solution could be to overcome the Federated Learning-related issues by preserving the privacy of end-user data. In this direction, the capabilities of Markov chains and associative rules are extended within a federated environment to face malware classification tasks in the IoT scenario. The presented approach, evaluated on several malware families, has achieved an average accuracy of 99% in the presence of centralized and decentralized unbalanced training/testing data by overcoming the most common state-of-the-art approaches. Also, its runtime performance is comparable with centralized ones by considering several non-independent and identically distributed dataset partitions, splitting criteria, and clients, respectively.
Gianni D'Angelo, Eslam Farsimadan, Massimo Ficco, Francesco Palmieri 0002, Antonio Robustelli
Future Gener. Comput. Syst.4
2023 A co-evolutionary genetic algorithm for robust and balanced controller placement in software-defined networks
abstract
The controller placement problem (CPP) is one of the main issues that need to be addressed in the context of Software Defined Networking (SDN), especially when different aspects are being considered, such as latency, capacity, reliability, and load balancing. Most of the solutions in the literature address these aspects by considering a fixed load for each controller and attempting to equally distribute the traffic demand of the switches among the controllers, which also have a fixed common capacity. On the contrary, in this work, the CPP is studied by considering load, controller capacity, and the failure probability of controllers and links as varying over time. The CPP is formulated in terms of a robust optimization problem, which, by introducing the concept of scenario, takes into account changes in the network status due to failures, load variations, and changes in switches’ demand and controllers’ capacity. The provided solution is robust, that is, neither controllers’ re-placement nor switches’ re-assignment is required as network conditions change. Besides, a co-evolutionary algorithm is provided to solve the aforementioned optimization problem. Two populations coevolve based on the concept of complementary evolution of allied species in nature. Experimental results on a set of real-world network topologies and comparisons with the state-of-the-art have proven the superiority of the proposal, in terms of better latency, load balancing and resilience, in solving the CPP under different network status changes that might occur over time.
Gianni D'Angelo, Francesco Palmieri 0002
J. Netw. Comput. Appl.2
2023 Enhancing COVID-19 tracking apps with human activity recognition using a deep convolutional neural network and HAR-images
abstract
With the emergence of COVID-19, mobile health applications have increasingly become crucial in contact tracing, information dissemination, and pandemic control in general. Apps warn users if they have been close to an infected person for sufficient time, and therefore potentially at risk. The distance measurement accuracy heavily affects the probability estimation of being infected. Most of these applications make use of the electromagnetic field produced by Bluetooth Low Energy technology to estimate the distance. Nevertheless, radio interference derived from numerous factors, such as crowding, obstacles, and user activity can lead to wrong distance estimation, and, in turn, to wrong decisions. Besides, most of the social distance-keeping criteria recognized worldwide plan to keep a different distance based on the activity of the person and on the surrounding environment. In this study, in order to enhance the performance of the COVID-19 tracking apps, a human activity classifier based on Convolutional Deep Neural Network is provided. In particular, the raw data coming from the accelerometer sensor of a smartphone are arranged to form an image including several channels (HAR-Image), which is used as fingerprints of the in-progress activity that can be used as an additional input by tracking applications. Experimental results, obtained by analyzing real data, have shown that the HAR-Images are effective features for human activity recognition. Indeed, the results on the k-fold cross-validation and obtained by using a real dataset achieved an accuracy very close to 100%.
Gianni D'Angelo, Francesco Palmieri 0002
Neural Comput. Appl.2
2023 Improved Protocols for Distributed Secret Sharing
abstract
In Distributed Secret Sharing schemes, secrets are encoded with shares distributed over multiple nodes of a network. Each involved party has access to a subset of the nodes and thus to a subset of the shares and is able to reconstruct a specific secret. Usually, these schemes are evaluated by measuring the required storage overhead, as well as the encoding and decoding complexities. In this paper, we provide new Distributed (multi) Secret Sharing Protocols for$(k,n)$-threshold access structures that improve on previous results, characterized by nearly-optimal storage overhead, achieving both storage optimality and a better encoding/decoding complexity. The protocols are also simpler than previous ones and allow for easier encoding.
Roberto De Prisco, Alfredo De Santis, Francesco Palmieri 0002
IEEE Trans. Dependable Secur. Comput.3
2023 Survivability Analysis of IoT Systems Under Resource Exhausting Attacks
abstract
Essential services in an Internet of Things (IoT)-based critical system should be continuously provided even when undesirable events like failures, attacks, and emergencies happen. In this work, we analyze the system’s ability to survive failures that are caused by resource exhaustion attacks. Such ability to survive means that the system’s services should be provided in compliance with the associated requirements also in presence of failures and other undesired events. Accordingly, we present a hybrid method (i.e., measurements- and model-based) to assess the expected survivability of an IoT system under resource-exhaustion attacks and, based on it, to optimize the preventive maintenance trigger period that maximizes survivability and minimizes the expected downtime cost. A realistic case study is implemented to emulate an IoT scenario and used to estimate the extent of resource consumption at each layer of the IoT stack when the system is subject to a resource-exhaustion attack. A semi-Markov process is then adopted to model the transient behavior of the system during an intrusion. The model is enriched with an additional state that represents a proactive recovery, in which the system is not available for a maintenance action aimed at preventing failure. The model solution gives the optimal maintenance triggering time.
Roberto Pietrantuono, Massimo Ficco, Francesco Palmieri 0002
IEEE Trans. Inf. Forensics Secur.3
2023 MLPKV: A Local Differential Multi-Layer Private Key-Value Data Collection Scheme for Edge Computing Environments
abstract
The existing solutions related to local differential privacy (LDP) in multi-layer networks for edge computing scenarios present several limitations in both key-value data heavy hitter identification and related frequency and mean estimation tasks. First, existing LDP approaches cannot effectively use edge nodes to improve their utility/performance. Secondly, there are many network transmission tasks in edge computing, which have relatively high requirements for communication and storage costs. Furthermore, the traditional privacy budget allocation cannot attain the best utilization. To solve the above problems, we propose MLPKV, a local differential multi-layer private key-value data collection scheme for edge computing, structured into three phases: dimensional reduction, padding-length estimation, and estimation. An improved EC-OLH algorithm is used to offload the computing efforts related to aggregation and estimation to edge nodes for achieving greater efficiency. In the dimensional reduction phase, a candidate set is generated to prune the domain of original data, which improves the estimation. In addition, our method groups users for completing the tasks in each phase to avoid additional errors caused by dividing the privacy budget, and proposes a new user division with an optimal grouping ratio. Finally, the proposed method was implemented in a proof-of-concept prototype system. We compare MLPKV with baseline methods such as PrivKV and PCKV. Experimental results on both synthetic and real-world datasets show that our method achieves better utility for heavy hitter identification, frequency, and mean estimations than other state-of-the-art mechanisms. For small data sets, our approach also provides high-accuracy estimation with a low privacy budget.
Xiaolong Xu 0002, Zexuan Fan, Marcello Trovati, Francesco Palmieri 0002
IEEE Trans. Inf. Forensics Secur.4
2022 A Galerkin Approach for Fractional Delay Differential Equations Using Hybrid Chelyshkov Basis Functions
Dajana Conte, Eslam Farsimadan, Leila Moradi, Francesco Palmieri 0002, Beatrice Paternoster
ICCSA (1)4
2022 Electricity production and consumption modeling through fuzzy logic
abstract
This paper proposes a prediction model based on fuzzy logic applied to anticipate electricity production and consumption in a building equipped with photovoltaics and connected to the grid. The goal is a smart energy management system able to make decisions and to adapt the consumption to the actual context and to the future electricity levels. The interest is to use as much electricity as possible from own production. The surplus is captured by an energy storage system or is sent to the grid. When no electricity is available from self-production, the grid is used to cover the necessities. The evaluations are performed on a data set collected in a real household. The proposed method is compared in terms of mean absolute error with other existing methods. The method developed based on fuzzy logic has an error of about 67 W, which places it among the most efficient models.
Lorena M. Olaru, Arpad Gellert, Ugo Fiore, Francesco Palmieri 0002
Int. J. Intell. Syst.4
2022 DNS tunnels detection via DNS-images
Gianni D'Angelo, Arcangelo Castiglione, Francesco Palmieri 0002
Inf. Process. Manag.3
2022 Artificial neural networks for resources optimization in energetic environment
abstract
Abstract Resource Planning Optimization (RPO) is a common task that many companies need to face to get several benefits, like budget improvements and run-time analyses. However, even if it is often solved by using several software products and tools, the great success and validity of the Artificial Intelligence-based approaches, in many research fields, represent a huge opportunity to explore alternative solutions for solving optimization problems. To this purpose, the following paper aims to investigate the use of multiple Artificial Neural Networks (ANNs) for solving a RPO problem related to the scheduling of different Combined Heat & Power (CHP) generators. The experimental results, carried out by using data extracted by considering a real Microgrid system, have confirmed the effectiveness of the proposed approach.
Gianni D'Angelo, Francesco Palmieri 0002, Antonio Robustelli
Soft Comput.2
2022 A genetic programming-based approach for classifying pancreatic adenocarcinoma: the SICED experience
abstract
Abstract Ductal adenocarcinoma of the pancreas is a cancer with a high mortality rate. Among the main reasons for this baleful prognosis is that, in most patients, this neoplasm is diagnosed at a too advanced stage. Clinical oncology research is now particularly focused on decoding the cancer molecular onset by understanding the complex biological architecture of tumor cell proliferation. In this direction, machine learning has proved to be a valid solution in many sectors of the biomedical field, thanks to its ability to mine useful knowledge by biological and genetic data. Since the major risk factor is represented by genetic predisposition, the aim of this study is to find a mathematical model describing the complex relationship existing between genetic mutations of the involved genes and the onset of the disease. To this end, an approach based on evolutionary algorithms is proposed. In particular, genetic programming is used, which allows solving a symbolic regression problem through the use of genetic algorithms. The identification of these correlations is a typical objective of the diagnostic approach and is one of the most critical and complex activities in the presence of large amounts of data that are difficult to correlate through traditional statistical techniques. The mathematical model obtained highlights the importance of the complex relationship existing between the different gene’s mutations present in the tumor tissue of the group of patients considered.
Gianni D'Angelo, Maria Nunzia Scoppettuolo, Anna Lisa Cammarota, Alessandra Rosati, Francesco Palmieri 0002
Soft Comput.5
2022 Maximum Network Lifetime Problem with Time Slots and coverage constraints: heuristic approaches
Raffaele Cerulli, Ciriaco D'Ambrosio, Antonio Iossa, Francesco Palmieri 0002
J. Supercomput.4
2022 Privacy-preserving Secure Media Streaming for Multi-user Smart Environments
abstract
Over the last years, our lifestyle has been positively upset by the sudden advent of technology. The Internet of Things (IoT), offering universal and ubiquitous connectivity to both people and objects, revealed to be the silver bullet for enabling a vast number of previously unexpected applications. In particular, media streaming providers are growing in business and scope, and we can forecast that soon, video streaming will substitute TV broadcasting activities. With the increasing success of multi-user smart environments, empowered by new-generation smart devices and IoT architectures, multimedia contents (i.e., images and videos) need to be effectively accessed anytime and anywhere. Recent advances in computer vision technologies have made the development of intelligent monitoring systems for video surveillance and ambient-assisted living. Such a scenario permits better integration among technologies, multimedia content, and end-users. However, there are several challenges, and some are still open. More precisely, due to the sensitivity of some multimedia content (e.g., video-surveillance streams), it is paramount to preserve users’ privacy. Again, it is necessary to guarantee the integrity of usage rights during any multimedia transmission process, starting from the video encoding phase. In this way, the private content is disclosed only when the stream is decoded on the other endpoint, by the legitimate user. In this article, we present a secure video transmission strategy that can address the challenges mentioned above. The proposed strategy takes advantage of both watermarking and video scrambling techniques to make it possible for the secure and privacy-preserving transmission of multimedia streaming. Through our proposal, multimedia streaming is of low quality and thus unusable. However, it can be fully recovered and enjoyed only by authorized users. Finally, due to its low complexity and energy-efficiency, our proposal is particularly suitable for onboard implementations.
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante
ACM Trans. Internet Techn.4
2021 Comparison Between Protein-Protein Interaction Networks CD4+T and CD8+T and a Numerical Approach for Fractional HIV Infection of CD4+T Cells
Eslam Farsimadan, Leila Moradi, Dajana Conte, Beatrice Paternoster, Francesco Palmieri 0002
ICCSA (1)5
2021 Vehicle-to-Everything (V2X) Communication Scenarios for Vehicular Ad-hoc Networking (VANET): An Overview
Eslam Farsimadan, Francesco Palmieri 0002, Leila Moradi, Dajana Conte, Beatrice Paternoster
ICCSA (8)2
2021 On the undetectability of payloads generated through automatic tools: A human-oriented approach
abstract
Abstract Nowadays, several tools have been proposed to support the operations performed during a security assessment process. In particular, it is a common practice to rely on automated tools to carry out some phases of this process in an automatic or semiautomatic way. In this article, we focus on tools for the automatic generation of custom executable payloads. Then, we will show how these tools can be transformed, through some human‐oriented modifications on the generated payloads, into threats for a given asset's security. The danger of such threats lies in the fact that they may not be detected by common antivirus (AVs). More precisely, in this article, we show a general approach to make a payload generated through automated tools run undetected by most AVs. In detail, we first analyze and explain most of the methods used by AVs to recognize malicious payloads and, for each one of them, we outline the relative strengths and flaws, showing how these flaws could be exploited using a general approach to evade AVs controls, by performing simple human‐oriented operations on the payloads. The testing activity we performed shows that our proposal is helpful in evading virtually all the most popular AVs on the market. Therefore, low‐skilled malicious users could easily use our approach.
Bruno Carpentieri, Arcangelo Castiglione, Francesco Palmieri 0002, Raffaele Pizzolante
Concurr. Comput. Pract. Exp.3
2021 Human oriented solutions for intelligent analysis, multimedia and communication systems
abstract
In recent years many user-oriented and personalized computing technologies have been developed, in which users are immersed in a virtual world and surrounded by processing units. Such computing technologies require distributed signals to be collected, and perform intelligent analysis with data fusion depending on user preferences and the surrounding environment. In such human-oriented analysis, it is also necessary to consider different user preferences and even behavioral factors, that influence the final computing results. Development of user-oriented computing approaches are especially apparent in virtual reality and interactive technologies, multimedia, and decision-making systems, as well as user-oriented security protocols. Such human-oriented protocols allow the intelligent analysis of a great amount of information, perform analytics processes, extract meaning and manage systems in a secure manner. These subjects, as well as a number of others, such as personalized protocols for data analysis and security, computing approaches based on behavioral or perceptual factors, and bio-inspired technologies for knowledge extraction, will form the topics of this Special Issue on “Human oriented solutions for intelligent analysis, multimedia and communication systems” in the journal Concurrency and Computation: Practice and Experience. For this Special Issue eleven articles of particular interest were selected, which present the most interesting research activities and results within the subject matter of this special issue. The article “Towards human oriented solutions for deep semantic data analysis” by Ogiela and Snasel,1 presents novel solutions for efficient semantic analysis of data on the basis of cognitive reasoning and an assessment of marketing preferences registered in the course of the human perception process. Obtaining information from data on the basis of its interpreted meaning, with a view to determine individual preferences, makes it possible to designate the set of features on whose occurrence (or absence) attention is focused and those features whose occurrence has an impact on ‘interest’ within a given piece of information, product, service, and so forth. The approach presented is based on application of cognitive resonance processes implemented in cognitive information systems. The article entitled “A method to generate context information sets from analysis results with a unified abstraction model based on an extension of data enrichment scheme” by Park et al.2 presents studies on a method for processing analysis modules that can enrich result datasets with context information based on a data abstraction model. Data abstraction provides not only capabilities for context-aware systems and users to inspect the context at four levels from raw datasets to situational relationships, but also supports unified context levels for each entity that can be deployed at any location where systems deal with context to provide dedicated services. The article “Customer-oriented sales modeling strategy in a big data environment” by Chen et al.3 presents a new idea for a data mining technology application in business services. Different factors are analyzed, which may affect the profit of shopping malls in a big data environment and the most critical factors are found by data mining technology. This allows different sales promotion strategies to be provided for merchants to facilitate the expansion of sales. In management, small profits and quick returns is a popular sales strategy used by many shopping malls to increase turnover. The article “An online cognitive authentication and trust evaluation application programming interface for cognitive security gateway based on distributed massive Internet of Things network” by Chen et al.4 presents a new online cognitive authentication and trust evaluation API for CSG based on distributed massive IoT network. An online identity generation API is proposed, together with the modified EPC Class 1 Gen2 tag translator which is used to create both provider's as well as client's online identities. The article entitled “Dealing with Noise in Crowdsourced GPS Human Trajectory Logging Data” by Adhinugraha et al.5 presents new solutions for classifying the noise that might be found from public GPS traces. More than 5300 trajectories that started in the state of Victoria, Australia, were considered, and noise was classified into four types: spike noise, point noise, track noise, and logical noise. The authors tested the behavior of noise when processed with convex hull-based non-map-matching preprocessing methods to reduce spikes, followed by granularity reduction to reduce point density. In the article “An Effective Architecture of Digital Twin System to Support Human Decision Making and AI-Driven Autonomy” by Mostafa et al.6 a data analytic maturity model is presented, which consists of four phases with ordered activities. It shows that any data analytic project needs to be gradually developed from foundations to powerful AI algorithms. The effort and time spent on a routine will create an exponential increase in business value. The digital twin starts in phase two which immediately follows the event that the big data infrastructure is established. It is started by shallowly replicating the characteristics, features and states of its physical twin, and then dives deeper to copy its behaviors, which is achieved by AI technologies, typically machine learning models. The article “On the Undetectability of Payloads generated through Automatic Tools: a Human-oriented Approach” by Carpentieri et al.7 describes tools for the automatic generation of custom executable payloads. Such payloads typically enable to improve the interaction between the security experts and the asset under evaluation. However, due to the actions they take (i.e., remote access, privilege escalation, and so forth), these payloads are most likely classified as malicious by AVs, thus preventing their execution on a system. This article aims to provide the research community with an awareness of the possible security threats that can arise from automated tools commonly used in security assessment processes. The article entitled “QoS-aware Big Service Composition using Distributed Co-Evolutionary Algorithm” by Dutta et al.8 presents an efficient QoS-aware big service composition model using a distributed co-evolutionary algorithm in Spark. In the proposed model the authors designed a distributed NSGA-III for finding the optimal Pareto front and a distributed multi-objective algorithm to compare the solutions of NSGA-III. They also discuss the parallel implementation of distributed co-evolutionary algorithm that makes the algorithms faster and scalable to find the near-optimal solution. The article entitled “Probability and Topic-Based Data Transmission Protocol” by Saito et al.9 presents the MPSFC model to efficiently implement the IoT, where mobile fog nodes such as vehicles communicate with other nodes over wireless networks. Here, each fog node calculates output data on input data received from other fog nodes and forwards the output data to other fog nodes in the epidemic routing way. The authors proposed the TTLBDT and PTBDT protocols and compared them with the TBDT protocol. The article “Implementation and evaluation of the information flow control for the Internet of Things” by Nakamura et al.10 describes the OI protocol and evaluates the authorization process of the OI protocol in terms of the execution time. In the evaluation, the authors make clear the features of the execution time of authorization processes for GET, PUT, POST, and DELETE operations in the OI protocol. The OI protocol was implemented on a hybrid device realized in Raspberry Pi 3 Model B+. The article entitled “Chatbots: Security, Privacy, Data Protection and Social Aspects” by Hasal et al.11 presents all security aspects concerning communication with chatbots. It provides a review describing important steps in chatbot design techniques considering the chatbot security. It also defines possible security threats and vulnerabilities, and presents detailed methods which allow the development of a safe chatbot platform. We believe that the articles included in this Special Issue will have a great impact for future scientific research, and also contribute to the studies conducted by other researchers and practitioners, who work in the area of advanced information processing systems and computer security. We would like to express my sincere appreciation of the valuable contributions made by all authors. We'd like also to express our special thanks to Professor David W. Walker from the School of Computer Science and Informatics, Cardiff University, UK, Editor-in-Chief of Concurrency and Computation: Practice and Experience, for allowing the publication of this Special Issue, and for his great support throughout the entire publication process. "Data sharing not applicable to this article as no datasets were generated or analysed during the current study"
Marek R. Ogiela, Wenny Rahayu, Francesco Palmieri 0002
Concurr. Comput. Pract. Exp.3
2021 A machine learning-based memory forensics methodology for TOR browser artifacts
abstract
Summary At present, 96% of the resources available into the World‐Wide‐Web belongs to the Deep Web, which is composed of contents that are not indexed by search engines. The Dark Web is a subset of the Deep Web, which is currently the favorite place for hiding illegal markets and contents. The most important tool that can be used to access the Dark Web is the Tor Browser. In this article, we propose a bottom‐up formal investigation methodology for the Tor Browser's memory forensics. Based on a bottom‐up logical approach, our methodology enables us to obtain information according to a level of abstraction that is gradually higher, to characterize semantically relevant actions carried out by the Tor browser. Again, we show how the proposed three‐layer methodology can be realized through open‐source tools. Also, we show how the extracted information can be used as input to a novel Artificial Intelligence‐based architecture for mining effective signatures capable of representing malicious activities in the Tor network. Finally, to assess the effectiveness of the proposed methodology, we defined three test cases that simulate widespread real‐life scenarios and discuss the obtained results. To the best of our knowledge, this is the first work that deals with the forensic analysis of the Tor Browser in a live system, in a formal and structured way.
Raffaele Pizzolante, Arcangelo Castiglione, Bruno Carpentieri, Roberto Contaldo, Gianni D'Angelo, Francesco Palmieri 0002
Concurr. Comput. Pract. Exp.6
2021 Effective classification of android malware families through dynamic features and neural networks
abstract
Due to their open nature and popularity, Android-based devices have attracted several end-users around the World and are one of the main targets for attackers. Because of the reasons given above, it is necessary to build tools that can reliably detect zero-day malware on these devices. At the moment, many of the frameworks that have been proposed to detect malware applications leverage Machine Learning (ML) techniques. However, an essential requirement to build these frameworks consists of using very large and sophisticated datasets for model construction and training purposes. Their success, indeed, strongly depends on the choice of the right features used for building a classification model providing adequate generalisation capability. Furthermore, the creation of a training dataset that well represents the malware properties and behaviour is one of the most critical challenges in malware analysis. Therefore, the main aim of this paper is proposing a new dataset called Unisa Malware Dataset (UMD) available on http://antlab.di.unisa.it/malware/, which is based on the extraction of static and dynamic features characterising the malware activities. Additionally, we will show some experiments concerning common ML tools to demonstrate how it is possible to build efficient ML-based malware classification frameworks using the proposed dataset.
Gianni D'Angelo, Francesco Palmieri 0002, Antonio Robustelli, Arcangelo Castiglione
Connect. Sci.2
2021 A stacked autoencoder-based convolutional and recurrent deep neural network for detecting cyberattacks in interconnected power control systems
abstract
Modern interconnected power grids are a critical target of many kinds of cyber-attacks, potentially affecting public safety and introducing significant economic damages. In such a scenario, more effective detection and early alerting tools are needed. This study introduces a novel anomaly detection architecture, empowered by modern machine learning techniques and specifically targeted for power control systems. It is based on stacked deep neural networks, which have proven to be capable to timely identify and classify attacks, by autonomously eliciting knowledge about them. The proposed architecture leverages automatically extracted spatial and temporal dependency relations to mine meaningful insights from data coming from the target power systems, that can be used as new features for classifying attacks. It has proven to achieve very high performance when applied to real scenarios by outperforming state-of-the-art available approaches.
Gianni D'Angelo, Francesco Palmieri 0002
Int. J. Intell. Syst.2
2021 A Cluster-Based Multidimensional Approach for Detecting Attacks on Connected Vehicles
abstract
Nowadays, modern vehicles are becoming even more connected, intelligent, and smart. A modern vehicle encloses several cyber-physical systems, such as actuators and sensors, which are controlled by electronic control units (ECUs). Such ECUs are connected through in-vehicle networks, and, in turn, such networks are connected to the Internet of Vehicles (IoV) to provide advanced and smart features. However, the increase in vehicle connectivity and computerization, although it brings clear advantages, it introduces serious safety problems that can also endanger the life of the driver and passengers of the vehicle, as well as that of pedestrians. Such problems are mainly caused by the security weaknesses affecting the controller area network (CAN) bus, used to exchange data between ECUs. In this article, we provide two algorithms that implement a data-driven anomaly detection system. The first algorithm (cluster-based learning algorithm), is used to learn the behavior of messages passing on the CAN bus, for base-lining purposes, while the second one (data-driven anomaly detection algorithm) is used to perform real-time classification of such messages (licit or illicit) for early alerting in the presence of malicious usages. The experimental results, obtained by using data coming from a real vehicle, have shown that our approach is capable of performing better than other anomaly detection-based approaches.
Gianni D'Angelo, Arcangelo Castiglione, Francesco Palmieri 0002
IEEE Internet Things J.3
2021 GGA: A modified genetic algorithm with gradient-based local search for solving constrained optimization problems
Gianni D'Angelo, Francesco Palmieri 0002
Inf. Sci.2
2021 Network traffic classification using deep convolutional recurrent autoencoder neural networks for spatial-temporal features extraction
Gianni D'Angelo, Francesco Palmieri 0002
J. Netw. Comput. Appl.2
2021 A Distributed Flow Correlation Attack to Anonymizing Overlay Networks Based on Wavelet Multi-Resolution Analysis
abstract
Government agencies rely more and more heavily on the availability of flexible and intelligent solutions for the interception and analysis of Internet-based telecommunications. Unfortunately, the global lawful interception market has been recently put into a corner by the emerging sophisticated encryption, obfuscation and anonymization technologies provided by modern overlay communication infrastructures. To face this challenge, this work proposes a novel strategy for defeating the anonymity of traffic flows, collected within and at the exit of these anonymizing networks, relying on distributed flow-capture, characterization and correlation attacks driven by wavelet-based multi-resolution analysis. Such a strategy, starting from a properly formalized attack model, results in an effective and promising framework that can be easily deployed on real-life network equipment and can potentially scale by working according to different distribution/parallelization scenarios.
Francesco Palmieri 0002
IEEE Trans. Dependable Secur. Comput.1
2020 On the File Recovery in Systems Infected by Ransomware
Raffaele D'Arco, Raffaele Pizzolante, Arcangelo Castiglione, Francesco Palmieri 0002
AINA4
2020 Network Forensics of WhatsApp: A Practical Approach Based on Side-Channel Analysis
Gianluca De Luca Fiscone, Raffaele Pizzolante, Arcangelo Castiglione, Francesco Palmieri 0002
AINA4
2020 Vulsploit: A Module for Semi-automatic Exploitation of Vulnerabilities
Arcangelo Castiglione, Francesco Palmieri 0002, Mariangela Petraglia, Raffaele Pizzolante
ICTSS2
2020 A Reliability and latency-aware routing framework for 5G transport infrastructures
Francesco Palmieri 0002
Comput. Networks1
2020 Compression-based steganography
abstract
Summary Conventional privacy‐enforcement mechanisms, such as encryption‐based ones, are frequently used to prevent third‐party eavesdroppers to intercept confidential information exchanged between two or more parties. However, the use of such mechanisms can be perceivable and it alerts the involved intercepting entities that could devote some effort in trying to remove the protection, eg, by cracking the encryption keys used or by exploiting the vulnerabilities of the technological solution used to protect the data. Sometimes, from the security point of view, avoiding to draw the attention or suspect to intermediate intercepting entities, may be better than protecting a data in a conventional manner. In such direction, one of the most effective approaches is hiding the secret information to be exchanged inside other data, through steganographic techniques. In this work, we exploit, for this specific purpose, the hierarchical structure of a compressed archive, as well as the algorithms and parameters used to create and maintain such archive. It is important to point out that, by doing this, the secret information is in no way semantically related to the contents of the compressed archive. This can be extremely useful in many cloud‐based situations where several confidential data is moved across multiple independent data center, which are under the control of different and not always fully trusted authorities. The effectiveness of this proposal has been assessed by using a properly designed and implemented prototype, where extensive tests have been performed within the context of a proof‐of‐concept.
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante
Concurr. Comput. Pract. Exp.4
2020 Securing PIN-based authentication in smartwatches with just two gestures
abstract
Summary Smartwatches are becoming increasingly ubiquitous as they offer new capabilities to develop sophisticated applications that make daily life easier and more convenient for consumers. The services provided include applications for mobile payment, ticketing, identification, access control, etc. While this makes modern smartwatches very powerful devices, it also makes them very attractive targets for attackers. Indeed, PINs and Pattern Lock have been widely used in smartwatches for user authentication. However, such authentication methods are not robust against various forms of cybersecurity attacks, such as side channel, phishing, smudge, shoulder surfing, and video‐recording attacks. Moreover, the recent adoption of hardware‐based solutions, like the Trusted Execution Environment (TEE), can mitigate only partially such problems. Thus, the user's security and privacy are at risk without a strong authentication scheme in place. In this work, we propose 2GesturePIN, a new authentication framework that allows users to authenticate securely to their smartwatches and related sensitive services through solely two gestures. 2GesturePIN leverages the rotating bezel or crown, which are the most intuitive ways to interact with a smartwatch, as a dedicated hardware. 2GesturePIN improves the resilience of the regular PIN authentication method against state‐of‐the‐art cybersecurity attacks while maintaining a high level of usability.
Meriem Guerar, Mauro Migliardi, Francesco Palmieri 0002, Luca Verderame, Alessio Merlo
Concurr. Comput. Pract. Exp.3
2020 Knowledge elicitation based on genetic programming for non destructive testing of critical aerospace systems
Gianni D'Angelo, Francesco Palmieri 0002
Future Gener. Comput. Syst.2
2020 Discovering genomic patterns in SARS-CoV-2 variants
abstract
SARS-CoV-2 is a novel severe acute respiratory syndrome-like coronavirus (SARS-CoV), which is responsible of the ongoing world pandemic of COVID-19 disease. Although many approaches are being investigated to address this issue, nowaday there are no vaccines available and there is little evidence supporting the efficiency of potential therapeutic agents. Moreover, the high mutation rate of this virus heavily affects the understanding of its evolution and diffusion mechanisms, and, in turn, the development of effective solutions. In this study, two novel algorithms are provided for finding out recurrent patterns of nucleotide subsequences of different SARS-CoV-2 genomes as a unique signature capable of identifying the most peculiar features of the pathogen. In particular, we provide several subsequence patterns related to the Spike glycoprotein, which is believed to be the main target for developing effective drugs and vaccines against the COVID-19 disease because of its role in the entrance of coronaviruses into host cells. The experimental results, obtained by analyzing 5000 genomes of SARS-CoV-2, have shown that the extracted patterns are able to recognize the Spyke protein in the 99.35% of the considered genomes. In addition, such patterns have proven to be highly discriminating with respect to other pathogenic genomes, such as SARS, Middle East respiratory syndrome, Nipah, and the streptococcus bacteria. We hope that the findings presented in this study can help specialists in speeding up the design of more accurate drugs or vaccines against SARS-CoV-2.
Gianni D'Angelo, Francesco Palmieri 0002
Int. J. Intell. Syst.2
2020 DLCD-CCE: A Local Community Detection Algorithm for Complex IoT Networks
abstract
Internet of Things (IoT) refers to the complex systems generated by the interconnections among widely available objects. Such interactions generate large networks, whose complexity needs to be addressed to provide suitable computationally efficient approaches. In this article, we propose a distributed local community detection algorithm based on specific properties of community center expansions (DLCD-CCE) for large-scale complex networks. The algorithm is evaluated via a prototype system, based on Spark, to verify its accuracy and scalability. The results demonstrate that compared to the typical local community detection algorithms, DLCD-CCE has better accuracy, stability, and scalability, and effectively overcomes the problem that existing algorithms are sensitive to the location of initial seeds.
Xiaolong Xu 0002, Marcello Trovati, Jeffrey Ray, Francesco Palmieri 0002, Hari Mohan Pandey
IEEE Internet Things J.5
2020 Transformative computing approaches for advanced management solutions and cognitive processing
Marek R. Ogiela, Francesco Palmieri 0002, Makoto Takizawa 0001
Inf. Process. Manag.2
2020 Securing visual search queries in ubiquitous scenarios empowered by smart personal devices
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante, Xiaofei Xing
Inf. Sci.4
2020 Special issue on advanced techniques for security and privacy of internet-of-things with machine learning
Jin Li 0002, Changyu Dong, Francesco Palmieri 0002
J. Netw. Comput. Appl.3
2020 Malware detection in mobile environments based on Autoencoders and API-images
Gianni D'Angelo, Massimo Ficco, Francesco Palmieri 0002
J. Parallel Distributed Comput.3
2020 Securing the internet of vehicles through lightweight block ciphers
Arcangelo Castiglione, Francesco Palmieri 0002, Francesco Colace, Marco Lombardi 0001, Domenico Santaniello, Giuseppe D'Aniello
Pattern Recognit. Lett.2
2020 A genetic approach for the maximum network lifetime problem with additional operating time slot constraints
Ciriaco D'Ambrosio, Antonio Iossa, Federica Laureana, Francesco Palmieri 0002
Soft Comput.4
2020 A machine learning evolutionary algorithm-based formula to assess tumor markers and predict lung cancer in cytologically negative pleural effusions
Stefano Elia, Gianni D'Angelo, Francesco Palmieri 0002, Roberto Sorge, Renato Massoud, Claudio Cortese, Georgia Hardavella, Alessandro De Stefano
Soft Comput.3
2020 Temporal convolutional neural (TCN) network for an effective weather forecasting using time-series data from the local weather station
abstract
Abstract Non-predictive or inaccurate weather forecasting can severely impact the community of users such as farmers. Numerical weather prediction models run in major weather forecasting centers with several supercomputers to solve simultaneous complex nonlinear mathematical equations. Such models provide the medium-range weather forecasts, i.e., every 6 h up to 18 h with grid length of 10–20 km. However, farmers often depend on more detailed short-to medium-range forecasts with higher-resolution regional forecasting models. Therefore, this research aims to address this by developing and evaluating a lightweight and novel weather forecasting system, which consists of one or more local weather stations and state-of-the-art machine learning techniques for weather forecasting using time-series data from these weather stations. To this end, the system explores the state-of-the-art temporal convolutional network (TCN) and long short-term memory (LSTM) networks. Our experimental results show that the proposed model using TCN produces better forecasting compared to the LSTM and other classic machine learning approaches. The proposed model can be used as an efficient localized weather forecasting tool for the community of users, and it could be run on a stand-alone personal computer.
Pradeep Hewage, Ardhendu Behera, Marcello Trovati, Ella Grishikashvili Pereira, Morteza Ghahremani, Francesco Palmieri 0002, Yonghuai Liu
Soft Comput.6
2020 CirclePIN: A Novel Authentication Mechanism for Smartwatches to Prevent Unauthorized Access to IoT Devices
abstract
In the last months, the market for personal wearable devices has been booming significantly, and, in particular, smartwatches are starting to assume a fundamental role in the Bring Your Own Device (BYOD) arena as well as in the more general Internet of Things (IoT) ecosystem, by acting both as sensitive data sources and as user identity proxies. These new roles, complementing the more traditional personal assistance and telemetry/tracking ones, open new perspectives in their integration in complex IoT-based critical infrastructures such as e-payment, health care monitoring, and emergency systems, as well as in their usage as remote control facilities in smart services. Users can access their IoT devices at any time from any place through smartwatches. We argue that this new scenario calls for a strengthened and more resilient authentication of users on these devices, despite their limitations in terms of dimensions and hardware constraints that may considerably affect the usability of security mechanisms. In this article, we present an innovative authentication scheme targeted at smartwatches, namely CirclePIN, that provides both resilience to most common attacks and a high level of usability in tests with real users.
Meriem Guerar, Luca Verderame, Alessio Merlo, Francesco Palmieri 0002, Mauro Migliardi, Luca Vallerini
ACM Trans. Cyber Phys. Syst.4
2020 Distributed Group Key Management for Event Notification Confidentiality Among Sensors
abstract
There is an increasing involvement of the Internet of Things (IoT) in many of our daily activities, with the aim of improving their efficiency and effectiveness. We are witnessing the advent of smart cities, in which IoT is exploited to improve the management of a city's assets, as well as smart factories, where IoT is paving the way for the forth industrial revolution. These applications and many other ones imply several non-functional requirements to be satisfied by the adopted IoT solution, where security assumes paramount importance. Secure communications among the IoT nodes are strongly needed due to the use of wireless technologies that are easy to eavesdrop, in order to steal valuable information. Accordingly, confidentiality is a fundamental prerequisite, but the existing solutions based on transport-level encryption are ineffective, while the ones with application-level encryption may be too expensive in terms of energy consumption. In this work, we propose a series of solutions and methods to achieve confidentiality with end-to-end guarantees, by using group-based keys within the context of a clustered and distributed key management framework. We have implemented such solutions on top of TinyOS, and assessed their achievable quality by means of the TOSSIM simulator.
Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis
IEEE Trans. Dependable Secur. Comput.4
2020 Low-Resource Footprint, Data-Driven Malware Detection on Android
abstract
Resource-constrained systems are becoming more and more common as users migrate from PCs to mobile devices and as IoT systems enter the mainstream. At the same time, it is not acceptable to reduce the level of security hence it is necessary to accommodate the required security into the system-imposed resource constraints. This paper introduces BAdDroIds, a mobile application leveraging machine learning for detecting malware on resource constrained devices. BAdDroIds executes in background and transparently analyzes the applications as soon as they are installed, i.e., before infecting the device. BAdDroIds relies on static analysis techniques and features provided by the Android OS to build up sound and complete models of Android apps in terms of permissions and API invocations. It uses ad-hoc supervised classification techniques to allow resource-efficient malware detection. By exploiting the intrinsic nature of data, it has been possible to implement a state-of-the-art data-driven model which provides deep insights on the detection problem and can be efficiently executed on the device itself as it requires a very limited computational effort. Besides its limited resource footprint, BAdDroIds is extremely effective: An extensive experimental evaluation shows that it outperforms the currently available solutions in terms of accuracy, which is around 99 percent.
Simone Aonzo, Alessio Merlo, Mauro Migliardi, Luca Oneto, Francesco Palmieri 0002
IEEE Trans. Sustain. Comput.5
2019 One-pass lossless data hiding and compression of remote sensing data
Bruno Carpentieri, Arcangelo Castiglione, Alfredo De Santis, Francesco Palmieri 0002, Raffaele Pizzolante
Future Gener. Comput. Syst.4
2019 Distributed temporal link prediction algorithm based on label propagation
Xiaolong Xu 0002, Marcello Trovati, Francesco Palmieri 0002, Georgios Kontonatsios, Aniello Castiglione
Future Gener. Comput. Syst.5
2019 Special Issue on Security and Privacy in Machine Learning
Jin Li 0002, Francesco Palmieri 0002, Yang Xiang 0001
Inf. Sci.2
2019 Detecting unfair recommendations in trust-based pervasive environments
Gianni D'Angelo, Francesco Palmieri 0002, Salvatore Rampone
Inf. Sci.2
2019 A data-driven approximate dynamic programming approach based on association rule learning: Spacecraft autonomy as a case study
Gianni D'Angelo, Massimo Tipaldi, Francesco Palmieri 0002, Luigi Glielmo
Inf. Sci.3
2019 Using generative adversarial networks for improving classification effectiveness in credit card fraud detection
Ugo Fiore, Alfredo De Santis, Francesca Perla, Paolo Zanetti, Francesco Palmieri 0002
Inf. Sci.5
2019 New energy-optimization challenges in the next-generation Internet ecosystem
Francesco Palmieri 0002
Inf. Sci.1
2019 Special issue on advances in security and privacy in IoT
Jin Li 0002, Francesco Palmieri 0002, Qiben Yan 0001
J. Netw. Comput. Appl.2
2019 Network anomaly detection based on logistic regression of nonlinear chaotic invariants
Francesco Palmieri 0002
J. Netw. Comput. Appl.1
2019 MIH-SPFP: MIH-based secure cross-layer handover protocol for Fast Proxy Mobile IPv6-IoT networks
Vishal Sharma 0001, Jianfeng Guan, Jiyoon Kim 0001, Soonhyun Kwon, Ilsun You, Francesco Palmieri 0002, Mario Collotta
J. Netw. Comput. Appl.6
2019 Leaf: An open-source cybersecurity training platform for realistic edge-IoT scenarios
Massimo Ficco, Francesco Palmieri 0002
J. Syst. Archit.2
2019 Guest Editorial: Soft Computing Applications for Novel and Upcoming Distributed and Parallel Systems From Cloud Computing and Beyond
abstract
The articles in this special issue aim at collecting contributions focused on the application of soft computing, including the areas of fuzzy logic, neural networks, evolutionary computing, rough sets, and other similar techniques, in novel distributed and/or parallel systems, where cloud computing is one of the widely known examples, in order to bring intelligence to all architectural layers for data processing, routing, etc. Brief summaries are provided for the included articles.
C. Choi, Francesco Palmieri 0002, J. W. Park, Hsing-Chung Chen
IEEE Trans. Ind. Informatics2
2018 Saving energy in aggressive intrusion detection through dynamic latency sensitivity recognition
Sherenaz W. Al-Haj Baddar, Alessio Merlo, Mauro Migliardi, Francesco Palmieri 0002
Comput. Secur.4
2018 Invisible CAPPCHA: A usable mechanism to distinguish between malware and humans on the mobile IoT
Meriem Guerar, Alessio Merlo, Mauro Migliardi, Francesco Palmieri 0002
Comput. Secur.4
2018 On the protection of consumer genomic data in the Internet of Living Things
Raffaele Pizzolante, Arcangelo Castiglione, Bruno Carpentieri, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Comput. Secur.5
2018 Information theoretic-based detection and removal of slander and/or false-praise attacks for robust trust management with Dempster-Shafer combination of linguistic fuzzy terms
abstract
Summary Critical systems are progressively abandoning the traditional isolated and closed architectures, and adopting more federated solutions, in order to deal with orchestrated decision making within large‐scale infrastructures. Such an increasing connectivity and the possibility of dynamically integrate constituents in a seamless manner by means of a decoupling middleware solution are causing the flouring of novel and previously unseen security threats, such as internal attacks conducted by camouflaged and/or compromised federated systems. Trust management is the most efficient way for dealing with such attacks, so that each constituent computes a trust degree of the other interacting ones based on the direct experiences and of collected reputation scores. An adversary may negatively affect the overall process with false reputations, which must not be considered when estimating a trust degree. Our work combines a multi‐criteria linguistic fuzzy term formulation of the trust degree with the concept of entropy for measuring the divergence of certain scores from the other ones and to avoid to consider them during reputation aggregation. A set of experiments have been conducted in order to measure the quality and effectiveness of the presented approach.
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002
Concurr. Comput. Pract. Exp.3
2018 CHIS: A big data infrastructure to manage digital cultural items
Aniello Castiglione, Francesco Colace, Vincenzo Moscato, Francesco Palmieri 0002
Future Gener. Comput. Syst.4
2018 On the optimal tuning and placement of FEC codecs within multicasting trees for resilient publish/subscribe services in edge-IoT architectures
Christian Esposito 0001, Andrea Bruno, Giuseppe Cattaneo, Francesco Palmieri 0002
Future Gener. Comput. Syst.4
2018 A coral-reefs and Game Theory-based approach for optimizing elastic cloud resource allocation
Massimo Ficco, Christian Esposito 0001, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.3
2018 Multi-layer cloud architectural model and ontology-based security service framework for IoT-based smart homes
Jinglong Zuo, Zhusong Liu, Aniello Castiglione, Francesco Palmieri 0002
Future Gener. Comput. Syst.5
2018 Loss-Tolerant Event Communications Within Industrial Internet of Things by Leveraging on Game Theoretic Intelligence
abstract
Internet of Things (IoT) is one of the key technologies paving the way for the next industrial revolution named as Industry 4.0, since it promises to realize smarter factories by optimizing costs and productivity. Traditionally, the adopted communication protocols among the sensors are required to manage the large scale of the infrastructure in terms on the high number of interconnected nodes and the massive volume of exchanged data. However, due to the key role of those Industrial IoT in exchanging business critical data, such protocols need to also provide high resiliency guarantees to the message exchange, with as few delivery misses as possible. The publish/subscribe interaction pattern and the protocol implementing it are a technically sound approach for achieving scalability and elasticity, thanks to their intrinsic decoupling among the interacting nodes. However, they are often unsuitable in their current form, because they provide only best-effort delivery guarantees, or they adopt naive solutions to achieve resilient communication, especially when wireless networks are used. This paper presents a clustered lightweight gossiping algorithm for resilient event based communications among the sensors, without requiring a pre-deployed brokering infrastructure supporting the adopted publish/subscribe protocol. A simulation-based assessment has been performed in order to empirically show the improvements in terms of successfully delivered notification without the excessive costs of the state-of-the-art solutions available in the literature.
Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Huimin Lu 0001
IEEE Internet Things J.4
2018 Building a network embedded FEC protocol by using game theory
Christian Esposito 0001, Arcangelo Castiglione, Francesco Palmieri 0002, Massimo Ficco
Inf. Sci.3
2018 Stackelberg games for modeling defense scenarios against cloud security threats
Agnieszka Jakobik, Francesco Palmieri 0002, Joanna Kolodziej
J. Netw. Comput. Appl.2
2018 Event-based sensor data exchange and fusion in the Internet of Things environments
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco, Ciprian Dobre, George V. Iordache, Florin Pop
J. Parallel Distributed Comput.3
2018 A scalable distributed machine learning approach for attack detection in edge computing environments
Rafal Kozik, Michal Choras, Massimo Ficco, Francesco Palmieri 0002
J. Parallel Distributed Comput.4
2018 Security and Privacy for Smart, Connected, and Mobile IoT Devices and Platforms
Karl Andersson 0001, Ilsun You, Francesco Palmieri 0002
Secur. Commun. Networks3
2018 Using Screen Brightness to Improve Security in Mobile Social Network Access
abstract
In the today's mobile communications scenario, smartphones offer new capabilities to develop sophisticated applications that seem to make daily life easier and more convenient for users. Such applications, which may involve mobile ticketing, identification, access control operations, etc., are often accessible through social network aggregators, that assume a fundamental role in the federated identity management space. While this makes modern smartphones very powerful devices, it also makes them very attractive targets for spyware injection. This kind of malware is able to bypass classic authentication measures and steal user credentials even when a secure element is used, and can, therefore, perform unauthorized mobile access to social network services without the user's consent. Such an event allows stealing sensitive information or even a full identity theft. In this work, we address this issue by introducing BrightPass, a novel authentication mechanism based on screen brightness. BrightPass allows users to authenticate safely with a PIN-based confirmation in the presence of specific operations on sensitive data. We compare BrightPass with existing schemes, in order to show its usability and security within the social network arena. Furthermore, we empirically assess the security of BrightPass through experimentation. Our tests indicate that BrightPass protects the PIN code against automatic submissions carried out by malware while granting fast authentication phases and reduced error rates.
Meriem Guerar, Mauro Migliardi, Alessio Merlo, Mohamed Benmohammed, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Dependable Secur. Comput.5
2018 Integrity for an Event Notification Within the Industrial Internet of Things by Using Group Signatures
abstract
In the last years, several academic research efforts have focused on security requirements, threat models, and attack taxonomies concerning the application of the Internet of Things (IoT) in critical systems. Since such systems are strongly data intensive, it is of pivotal importance to provide integrity for the messages moving throughout the IoT infrastructure by means of publish/subscribe services. Integrity provisioning in industrial IoT scenarios has received marginal attention with respect to other primary security features. The existing solutions are lacking the needed focus on the peculiarities of the event notification and on the demand introduced by resource-constrained devices. This work contributes by applying group signatures so as to avoid managing certificates, violating the spatial decoupling, or implying an excessive resource usage. A proof-of-concept prototype of the proposed solution has been realized for platforms based on TinyOS, and simulations with TOSSIM have been conducted in order to empirically assess its performance and effectiveness.
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis
IEEE Trans. Ind. Informatics3
2017 Dynamic Latency Sensitivity Recognition: An Application to Energy Saving
Sherenaz W. Al-Haj Baddar, Alessio Merlo, Mauro Migliardi, Francesco Palmieri 0002
GPC4
2017 A collaborative clinical analysis service based on theory of evidence, fuzzy linguistic sets and prospect theory and its application to craniofacial disorders in infants
Arcangelo Castiglione, Raffaele Pizzolante, Christian Esposito 0001, Alfredo De Santis, Francesco Palmieri 0002, Aniello Castiglione
Future Gener. Comput. Syst.5
2017 Improving the gossiping effectiveness with distributed strategic learning (Invited paper)
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.3
2017 Trust management for distributed heterogeneous systems by using linguistic term sets and hierarchies, aggregation operators and mechanism design
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco
Future Gener. Comput. Syst.3
2017 Supporting dynamic updates in storage clouds with the Akl-Taylor scheme
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Xinyi Huang 0001, Aniello Castiglione
Inf. Sci.4
2017 Layered multicast for reliable event notification over large-scale networks
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002
Inf. Sci.3
2017 Bayesian resource discovery in infrastructure-less networks
Francesco Palmieri 0002
Inf. Sci.1
2017 A wave propagation-based adaptive probabilistic broadcast containment strategy for reactive MANET routing protocols
Francesco Palmieri 0002
Pervasive Mob. Comput.1
2017 Developing a trust model for pervasive computing based on Apriori association rules learning and Bayesian classification
Gianni D'Angelo, Salvatore Rampone, Francesco Palmieri 0002
Soft Comput.3
2017 On-Board Format-Independent Security of Functional Magnetic Resonance Images
abstract
Functional magnetic resonance imaging (fMRI) provides an effective and noninvasive tool for researchers to understand cerebral functions and correlate them with brain activities. In addition, with the ever-increasing diffusion of the Internet, such images may be exchanged in several ways, allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern due to their special characteristics arising from strict ethics and legislative and diagnostic implications. Again, the risks increase when dealing with open environments like the Internet. For this reason, security mechanisms that ensure protection of such data are strongly required. However, we remark that the mechanisms commonly employed for data protection are doomed to fail when dealing with imaging data. In this article, we propose a novel watermarking scheme explicitly addressed for this type of imaging. Such a scheme can be used for several purposes, particularly to ensure authenticity and integrity. Moreover, we show how to integrate our scheme within commercial off-the-shelf fMRI system. Finally, the validity and the efficiency of our scheme has been assessed through testing.
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Barbara Masucci, Bruno Carpentieri, Alfredo De Santis, Aniello Castiglione
ACM Trans. Embed. Comput. Syst.3
2017 Exploiting Battery-Drain Vulnerabilities in Mobile Smart Devices
abstract
Differently from attacks aimed at gaining control of the resources of a mobile device, energy-related attacks have the essential goal of significantly raising the energy demand on the victim side, without apparently affecting its activities. It is a fundamental point to highlight how such a goal can possibly be accomplished by mounting well-known canonical attacks and waiting for the system defenses to detect and stop them. In such an endeavor, defenses require additional amounts of energy which eventually render the mobile device completely useless. In the System on Chip (SoC) architecture, many components, each with a separate function, are integrated. As the total energy adsorption is the composition of the energy consumptions of individual components, each component may be the target of an energy-based attack. This work analyzes and discusses the effects and implication of new energy-based Denial of Service attacks based on the proper solicitation of hardware-layer encode/decode capabilities by using specifically crafted multimedia resources, in order to introduce an anomalous battery drain, and hence significantly shorten the overall battery lifetime in mobile smart devices. These attacks do not require physical access nor compromise of the target device, and they take advantage of new HTML5 functionalities that can be properly triggered during normal browsing activity. The more significant result is that the Digital Signal Processor (DSP) offers an exploitable attack surface to be kept into consideration early in the design process. Countermeasures include special filtering rules that prevent “irrelevant” content from reaching the DSP or, in a more far-reached perspective, the introduction of a power-draw controller on the SoC with the purpose of monitoring energy consumption and raising alerts.
Ugo Fiore, Aniello Castiglione, Alfredo De Santis, Francesco Palmieri 0002
IEEE Trans. Sustain. Comput.4
2016 On the Relations Between Security Notions in Hierarchical Key Assignment Schemes for Dynamic Structures
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione
ACISP (2)4
2016 A hybrid load-balancing and energy-aware RWA algorithm for telecommunication networks
Sergio Ricciardi, David Sembroiz-Ausejo, Francesco Palmieri 0002, Germán Santos-Boada, Jordi Perelló, Davide Careglio
Comput. Commun.3
2016 An HLA-based framework for simulation of large-scale critical systems
abstract
Summary Evaluating the dependability of large‐scale critical infrastructures is a very difficult task that requires sophisticated modeling practices and experimentation environments/infrastructures. In particular, simulation of complex distributed systems require the integration of several different simulation tools and real‐time prototypes or emulated subsystems, which have to inter‐operate in a coordinated way. This paper presents a framework integrating simulation and emulation‐based subsystems, which is able to provide greater realism of the scenario under test. However, integrating simulation and emulation is a challenging issue because of the different time domains and to the communication overhead between the different time models, as well as to the large number of involved entities. Therefore, the high level architecture has been used to perform integration in a robust and standardized scenario. A cloud‐based virtualization platform has been adopted in order to reproduce complex system architectures on an elastic and adaptive locally controlled testbed. Copyright © 2015 John Wiley & Sons, Ltd.
Massimo Ficco, Giovanni Avolio, Francesco Palmieri 0002, Aniello Castiglione
Concurr. Comput. Pract. Exp.3
2016 GRASP-based resource re-optimization for effective big data access in federated clouds
Francesco Palmieri 0002, Ugo Fiore, Sergio Ricciardi, Aniello Castiglione
Future Gener. Comput. Syst.1
2016 A secure payment system for multimedia on demand on mobile VANET clouds
abstract
Abstract The more recent advances in network communication and cloud computing technologies have the potential of significantly improving traveling experience by providing value‐added services, such as multimedia on demand (MoD), in vehicular ad hoc networks, where the involved vehicles are provided with enough communication, storage, and computing capabilities. In this scenario, despite many consolidated mobile cloud solutions and pay‐per‐view systems have been developed and widely deployed in public transportation, the security and privacy of mobile users, mainly concerning the association between users' identities and requested multimedia contents, still presents several open challenges. Mainly, providing pay‐per‐view services in vehicular clouds while protecting the passenger's anonymity and simultaneously ensuring the robustness of the payment system has become an important issue.Accordingly, we present a novel smart card‐based MoD payment solution, to be used in mobile cloud‐empowered public transportation systems, that not only guarantees the passenger's anonymity but also uses a personal trusted device to protect the passenger's sensitive information so that he can enjoy the multimedia contents during the long hours of travel. In the future, such scheme can become common practice on MoD‐related equipment in vehicular ad hoc networks, thereby enhancing the competitiveness of public transport companies. Copyright © 2016 John Wiley & Sons, Ltd.
Chin-Ling Chen, Yu-Fan Lin, Aniello Castiglione, Francesco Palmieri 0002
Secur. Commun. Networks4
2016 Smart Cloud Storage Service Selection Based on Fuzzy Logic, Theory of Evidence and Game Theory
abstract
Cloud platforms encompass a large number of storage services that can be used to manage the needs of customers. Each of these services, offered by a different provider, is characterized by specific features, limitations and prices. In presence of multiple options, it is crucial to select the best solution fitting the customer requirements in terms of quality of service and costs. Most of the available approaches are not able to handle uncertainty in the expression of subjective preferences from customers, and can result in wrong (or sub-optimal) service selections in presence of rational/selfish providers, exposing untrustworthy indications concerning the quality of service levels and prices associated to their offers. In addition, due to its multi-objective nature, the optimal service selection process results in a very complex task to be managed, when possible, in a distributed way, for well-known scalability reasons. In this work, we aim at facing the above challenges by proposing three novel contributions. The fuzzy sets theory is used to express vagueness in the subjective preferences of the customers. The service selection is resolved with the distributed application of fuzzy inference or Dempster-Shafer theory of evidence. The selection strategy is also complemented by the adoption of a game theoretic approach for promoting truth-telling ones among service providers. We present empirical evidence of the proposed solution effectiveness through properly crafted simulation experiments.
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Computers3
2016 Hierarchical and Shared Access Control
abstract
Access control ensures that only the authorized users of a system are allowed to access certain resources or tasks. Usually, according to their roles and responsibilities, users are organized in hierarchies formed by a certain number of disjoint classes. Such hierarchies are implemented by assigning a key to each class, so that the keys for descendant classes can be efficiently derived from classes higher in the hierarchy. However, pure hierarchical access may represent a limitation in many real-world cases. In fact, sometimes it is necessary to ensure access to a resource or task by considering both its directly responsible user and a group of users possessing certain credentials. In this paper, we first propose a novel model that generalizes the conventional hierarchical access control paradigm, by extending it to certain additional sets of qualified users. Afterward, we propose two constructions for hierarchical key assignment schemes in this new model, which are provably secure with respect to key indistinguishability. In particular, the former construction relies on both symmetric encryption and perfect secret sharing, whereas, the latter is based on public-key threshold broadcast encryption.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Jin Li 0002, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.4
2016 Cryptographic Hierarchical Access Control for Dynamic Structures
abstract
A hierarchical key assignment scheme is a method to assign some private information and encryption keys to a set of classes in a partially ordered hierarchy, in such a way that the private information of a higher class can be used to derive the keys of all classes lower down in the hierarchy. Sometimes, it is necessary to make dynamic updates to the hierarchy, in order to implement an access control policy which evolves with time. All security models for hierarchical key assignment schemes have been designed to cope with static hierarchies and do not consider the issue of performing dynamic updates to the hierarchy. In this paper, we define the concept of hierarchical key assignment schemes supporting dynamic updates, formalizing the relative security model. In particular, we provide the notion of security with respect to key indistinguishability, by considering the dynamic changes to the hierarchy. Moreover, we show how to construct a hierarchical key assignment scheme supporting dynamic updates, by using as a building block a symmetric encryption scheme. The proposed construction is provably secure with respect to key indistinguishability, and provides efficient key derivation and updating procedures, while requiring each user to store only a single private key.
Arcangelo Castiglione, Alfredo De Santis, Barbara Masucci, Francesco Palmieri 0002, Aniello Castiglione, Xinyi Huang 0001
IEEE Trans. Inf. Forensics Secur.4
2015 On the Protection of fMRI Images in Multi-domain Environments
abstract
Functional Magnetic Resonance Imaging provides researchers with an effective and non-invasive tool to understand cerebral functions and correlate them with brain activities. With the ever increasing diffusion of the Internet such images may be exchanged in several ways, thus allowing new research and medical services. On the other hand, ensuring the security of exchanged fMRI data becomes a main concern, due to the special characteristics arising from strict ethics, legislative and diagnostic implications. So it is very important to prevent unauthorized manipulation and misappropriation of such images. The risks are increased when dealing with open environments like the Internet. For this reason, security mechanisms which ensure protection of such data are required. In this paper we introduce a watermarking scheme explicitly designed for this kind of images. In particular, such a scheme belongs to the category of fragile reversible watermarking. The validity of this scheme has been demonstrated through testing. Finally, by using the proposed scheme, we show how to create a distributed security solution that models a multi-domain environment, for ensuring authenticity and integrity of such images.
Arcangelo Castiglione, Alfredo De Santis, Raffaele Pizzolante, Aniello Castiglione, Vincenzo Loia, Francesco Palmieri 0002
AINA6
2015 Heterogeneous Network Handover Using 3GPP ANDSF
abstract
In this paper, we propose an improved IP-based handover scheme, named the Heterogeneous Network Handover by using 3GPP ANDSF (HNH3A for short) for S-PMIPv6 where S-PMIPv6 is a MIPv6 family protocol developed in one of our previous studies, and ANDSF (standing for Access Network Discovery and Selection Function) is an entity within an evolved packet core (EPC) of the system architecture evolution (SAE) for 3GPP compliant mobile networks. The purpose of using the ANDSF is to assist user equipment (UE) to discover non-3GPP access networks, such as WiFi or WIMAX. The HNH3A can help the handover among mobile WiMAX (i.e., Worldwide Interoperability for Microwave Access), 3GPP (i.e., 3rd Generation Partnership Project) family (including 3GPP systems, 3G LTE and 4G LTE-A) and WiFi based on existing handover techniques among the three heterogeneous networks. The analytical results demonstrate that the HNH3A can effectively mitigate handover delays and handover signaling costs.
Chin-Yu Liu, Fang-Yie Leu, Jung-Chun Liu, Aniello Castiglione, Francesco Palmieri 0002
AINA5
2015 Modeling security requirements for cloud-based system development
abstract
Summary The Cloud Computing paradigm provides a new model for the more flexible utilization of computing and storage services. However, such enhanced flexibility, which implies outsourcing the data and business applications to a third party, may introduce critical security issues. Therefore, there is a clear necessity of new security paradigms able to face all the problems introduced by the cloud approach. Although, in the last years, several solutions have been proposed, the implementation of secure cloud applications and services is still a complex and far from consolidated task. Starting from these considerations, this work fosters the development of a methodology that considers security concerns as an integral part of cloud‐based applications design and implementation. Accordingly, we present a set of stereotypes that defines a vocabulary for annotating Unified Modeling Language based models with information relevant for integrating the specification of security requirements into cloud architectures. This approach can be used to significantly improve productivity and overall success in the development of secure distributed cloud applications and systems. Copyright © 2014 John Wiley & Sons, Ltd.
Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Concurr. Comput. Pract. Exp.2
2015 Cloud-based adaptive compression and secure management services for 3D healthcare data
Arcangelo Castiglione, Raffaele Pizzolante, Alfredo De Santis, Bruno Carpentieri, Aniello Castiglione, Francesco Palmieri 0002
Future Gener. Comput. Syst.6
2015 Modeling energy-efficient secure communications in multi-mode wireless mobile devices
Arcangelo Castiglione, Francesco Palmieri 0002, Ugo Fiore, Aniello Castiglione, Alfredo De Santis
J. Comput. Syst. Sci.2
2015 Energy efficiency of elastic frequency grids in multilayer IP/MPLS-over-flexgrid networks
Sergio Ricciardi, Francesco Palmieri 0002, Aniello Castiglione, Davide Careglio
J. Netw. Comput. Appl.2
2015 A knowledge-based platform for Big Data analytics based on publish/subscribe services and stream processing
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Knowl. Based Syst.3
2015 Secure and reliable data communication in developing regions and rural areas
Arcangelo Castiglione, Raffaele Pizzolante, Francesco Palmieri 0002, Alfredo De Santis, Bruno Carpentieri, Aniello Castiglione
Pervasive Mob. Comput.3
2015 Modeling performances of concurrent big data applications
abstract
Summary Big Data applications are characterized by a non‐negligible number of complex parallel transactions on a huge amount of data that continuously varies, generally increasing over time. Because of the amount of needed resources, the ideal runtime scenario for these applications is based on complex cloud computing and storage infrastructures, providing a scalable degree of parallelism together with isolation between different applications and resource abstraction. However, such additional abstraction degree also introduces significant complexity in performance modeling and decision making. Potential concurrency of many applications on the same cloud infrastructure has to be evaluated, and, simultaneously, scalability of applications over time has to be studied through proper modeling practices, in order to predict the system behavior as the usage patterns evolve and the load increases. For this purpose, in this paper, we propose an analytic modeling technique based on the use of Markovian Agents and Mean Field Analysis that allows the effective description of different concurrent Big Data applications on a same, multi‐site cloud infrastructure, accounting for mutual interactions, in order to support the careful evaluation of several elements in terms of real costs/risks/benefits for correctly dimensioning and allocating the resources and verifying the existing service level agreements. Copyright © 2014 John Wiley & Sons, Ltd.
Aniello Castiglione, Marco Gribaudo, Mauro Iacono, Francesco Palmieri 0002
Softw. Pract. Exp.4
2015 Energy-oriented denial of service attacks: an emerging menace for large cloud infrastructures
Francesco Palmieri 0002, Sergio Ricciardi, Ugo Fiore, Massimo Ficco, Aniello Castiglione
J. Supercomput.1
2015 A triadic closure and homophily-based recommendation system for online social networks
Giuliana Carullo, Aniello Castiglione, Alfredo De Santis, Francesco Palmieri 0002
World Wide Web4
2014 An Efficient and Transparent One-Time Authentication Protocol with Non-interactive Key Scheduling and Update
abstract
Authentication protocols prevent resources to be accessed by unauthorized users. Password authentication is one of the simplest and most convenient authentication mechanism over insecure networks and, in particular, the one-time authentication mechanism, in which the password is valid only for one login session or transaction are a good compromise between simplicity of use and security. Nowadays many of such protocols have been proposed to implement that type of authentication. However, most of them have several drawbacks because they are characterized by considerable overhead in the Key Setup, Key Scheduling and Key Update phases. In addition, they are often vulnerable to several known attacks and are not particularly suitable to be used by mobile terminals. Furthermore, they often rely on smart-card and other hardware tokens, thus requiring an active participation by the user. In this paper, we present a robust one-time authentication protocol, based on two cryptographically strong building blocks, namely, the Authenticated Key Exchange key exchange and the keyed Hash Message Authentication Code (HMAC), that provides several advantages with respect to most of the available solutions at the state of the art. First, it enables transparent mutual authentication between two endpoints. Moreover, Key Setup, Key Scheduling and Key Update operations are accomplished independently by both endpoints, without requiring any interaction among them, thus ensuring the fully independence by any Trusted Third Party. Finally, the proposed protocol is cryptographically secure, under standard assumptions against most of the already known OTP attacks.
Arcangelo Castiglione, Alfredo De Santis, Aniello Castiglione, Francesco Palmieri 0002
AINA4
2014 Multimedia-based battery drain attacks for Android devices
abstract
People using smartphones to connect to the Internet for day-life activities has overtaken the number of people using canonical PCs. This lead to a huge quantity of security threats that usually tend to penetrate the defenses of a smartphone in order to gain control of its resources. Differently, energy-based attacks have the objective of increasing the energy consumption of the victim device. It is important to highlight that this objective could be possibly achieved by just activating the system's defenses as a consequence of canonical attacks and letting the system defenses detect and (try to) defeat them. These activities consume additional energy and could led the mobile device to its complete uselessness. In this paper, an energy-based attack based on soliciting hardware-level encoding/decoding functions through properly crafted multimedia files is analyzed and its impact evaluated. Such kind of attacks are performed without accessing the device by taking advantage of the new HTML5 functionalities. A series of experiments have been performed in order to understand which are the codecs that have a more relevant impact on energy consumption, and, as a consequence, that make the attack more effective.
Ugo Fiore, Francesco Palmieri 0002, Aniello Castiglione, Vincenzo Loia, Alfredo De Santis
CCNC2
2014 A distributed approach to network anomaly detection based on independent component analysis
abstract
SUMMARY Network anomalies, circumstances in which the network behavior deviates from its normal operational baseline, can be due to various factors such as network overload conditions, malicious/hostile activities, denial of service attacks, and network intrusions. New detection schemes based on machine learning principles are therefore desirable as they can learn the nature of normal traffic behavior and autonomously adapt to variations in the structure of ‘normality’ as well as recognize the significant deviations as suspicious or anomalous events. The main advantages of these techniques are that, in principle, they are not restricted to any specific environment and that they can provide a way of detecting unknown attacks. Detection performance is directly correlated with the traffic model quality, in terms of ability of representing the traffic behavior from its most characterizing internal dynamics. Starting from these ideas, we developed a two‐stage anomaly detection strategy based on multiple distributed sensors located throughout the network. By using Independent Component Analysis , the first step, modeled as a Blind Source Separation problem, extracts the fundamental traffic components (the ‘source’ signals), corresponding to the independent traffic dynamics, from the multidimensional time series incoming from the sensors, corresponding to the perceived ‘mixed/aggregate’ effect of traffic on their interfaces. These components will be used to build the baseline traffic profiles needed in the second supervised phase, based on a binary classification scheme (detection is casted into an anomalous/normal classification problem) driven by machine learning‐inferred decision trees. Copyright © 2013 John Wiley & Sons, Ltd.
Francesco Palmieri 0002, Ugo Fiore, Aniello Castiglione
Concurr. Comput. Pract. Exp.1
2014 Exploiting mean field analysis to model performances of big data architectures
Aniello Castiglione, Marco Gribaudo, Mauro Iacono, Francesco Palmieri 0002
Future Gener. Comput. Syst.4
2014 A botnet-based command and control approach relying on swarm intelligence
Aniello Castiglione, Roberto De Prisco, Alfredo De Santis, Ugo Fiore, Francesco Palmieri 0002
J. Netw. Comput. Appl.5
2014 Hybrid indoor and outdoor location services for new generation mobile terminals
Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione
Pers. Ubiquitous Comput.2
2014 A Denial of Service Attack to UMTS Networks Using SIM-Less Devices
abstract
One of the fundamental security elements in cellular networks is the authentication procedure performed by means of the Subscriber Identity Module that is required to grant access to network services and hence protect the network from unauthorized usage. Nonetheless, in this work we present a new kind of denial of service attack based on properly crafted SIM-less devices that, without any kind of authentication and by exploiting some specific features and performance bottlenecks of the UMTS network attachment process, are potentially capable of introducing significant service degradation up to disrupting large sections of the cellular network coverage. The knowledge of this attack can be exploited by several applications both in security and in network equipment manufacturing sectors.
Alessio Merlo, Mauro Migliardi, Nicola Gobbo, Francesco Palmieri 0002, Aniello Castiglione
IEEE Trans. Dependable Secur. Comput.4
2014 A secure file sharing service for distributed computing environments
Aniello Castiglione, Luigi Catuogno, Aniello Del Sorbo, Ugo Fiore, Francesco Palmieri 0002
J. Supercomput.5
2013 FeelTrust: Providing Trustworthy Communications in Ubiquitous Mobile Environment
abstract
The growing intelligence and popularity of smartphones and the advances in Mobile Ubiquitous Computing have resulted in rapid proliferation of data-sharing applications. Instances of these applications include pervasive social networking, games, file sharing and so on. In such scenarios, users are usually involved in selecting the peers with whom communication should take place, continuously facing trust issues. Unfortunately, providing trust support in a pervasive world is challenging due to peer mobility and lack in central control. We propose a novel approach that establishes trust leveraging users' profiles: humans today produce rich strings of unique data twenty-four hours a day. These information enables a task-aware trust model, namely a finer-grained model in which users are classified as trusted or not depending on the intended business activity. However, simply collecting user's interests may be insufficient to provide a reasonable trust management system. In order to enable the system to recognize malicious users, we include a recommendation subsystem based on the Wilson score confidence interval. It has been designed to be lightweight, minimizing battery depletion. It also protects user privacy. To make our approach fully deployable, it supports two modalities: a TPM-based one and a TPM-less one. The former gives more security guarantees and ensures a fully distributed approach. The latter, requires a Trusted Authority to avoid feedbacks to get tampered and is no more fully distributed.
Giuliana Carullo, Aniello Castiglione, Giuseppe Cattaneo, Alfredo De Santis, Ugo Fiore, Francesco Palmieri 0002
AINA6
2013 Scalable service discovery in ubiquitous and pervasive computing architectures: A percolation-driven approach
Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2013 A distributed scheduling framework based on selfish autonomous agents for federated cloud environments
Francesco Palmieri 0002, Luigi Buonanno, Salvatore Venticinque, Rocco Aversa, Beniamino Di Martino
Future Gener. Comput. Syst.1
2013 Network anomaly detection with the restricted Boltzmann machine
Ugo Fiore, Francesco Palmieri 0002, Aniello Castiglione, Alfredo De Santis
Neurocomputing2
2012 An energy-aware dynamic RWA framework for next-generation wavelength-routed networks
Sergio Ricciardi, Francesco Palmieri 0002, Ugo Fiore, Davide Careglio, Germán Santos-Boada, Josep Solé-Pareta
Comput. Networks2
2012 Selfish routing and wavelength assignment strategies with advance reservation in inter-domain optical networks
Francesco Palmieri 0002, Ugo Fiore, Sergio Ricciardi
Comput. Commun.1
2012 Percolation-based routing in the Internet
Francesco Palmieri 0002
J. Syst. Softw.1
2011 New Steganographic Techniques for the OOXML File Format
Aniello Castiglione, Bonaventura D'Alessio, Alfredo De Santis, Francesco Palmieri 0002
ARES4
2011 Energy-Aware RWA for WDM Networks with Dual Power Sources
abstract
Energy consumption and the concomitant Green House Gases (GHG) emissions of network infrastructures are becoming major issues in the Information and Communication Society (ICS). Current optical network infrastructures (routers, switches, line cards, signal regenerators, optical amplifiers, etc.) have reached huge bandwidth capacity but the development has not been compensated adequately as for their energy consumption. Renewable energy sources (e.g. solar, wind, tide, etc.) are emerging as a promising solution both to achieve drastically reduction in GHG emissions and to cope with the growing power requirements of network infrastructures. The main contribution of this paper is the formulation and the comparison of several energy-aware static routing and wavelength assignment (RWA) strategies for wavelength division multiplexed (WDM) networks where optical devices can be powered either by renewable or legacy energy sources. The objectives of such formulations are the minimization of either the GHG emissions or the overall network power consumption. The solutions of all these formulations, based on integer linear programming (ILP), have been observed to obtain a complete perspective and estimate a lower bound for the energy consumption and the GHG emissions attainable through any feasible dynamic energy-aware RWA strategy and hence can be considered as a reference for evaluating optimal energy consumption and GHG emissions within the RWA context. Optimal results of the ILP formulations show remarkable savings both on the overall power consumption and on the GHG emissions with just 25% of green energy sources.
Sergio Ricciardi, Davide Careglio, Francesco Palmieri 0002, Ugo Fiore, Germán Santos-Boada, Josep Solé-Pareta
ICC3
2010 Energy-Oriented Models for WDM Networks
Sergio Ricciardi, Davide Careglio, Francesco Palmieri 0002, Ugo Fiore, Germán Santos-Boada, Josep Solé-Pareta
BROADNETS3
2010 Insights into peer to peer traffic through nonlinear analysis
abstract
The enormous growth in popularity of peer-to-peer applications has recently introduced great interest in understanding the associated traffic workload and behavior. The goal of this work is determining the fundamental dynamics characterizing such traffic that can be used to develop simple and effective prediction models and to illustrate and describe fundamental performance issues. The discovery of nonlinear traffic dynamics, due to the very complex characteristics of the involved time series, led us to use several nonlinear analysis techniques and tools evidencing the presence of chaos-related structures together with self-similarity and long-range dependence features.
Francesco Palmieri 0002, Ugo Fiore
ISCC1
2010 A Fault Avoidance Strategy Improving the Reliability of the EGI Production Grid Infrastructure
Francesco Palmieri 0002, Silvio Pardi, Paolo Veronesi
OPODIS1
2010 A GRASP-based network re-optimization strategy for improving RWA in multi-constrained optical transport infrastructures
Francesco Palmieri 0002, Ugo Fiore, Sergio Ricciardi
Comput. Commun.1
2010 Network anomaly detection through nonlinear analysis
Francesco Palmieri 0002, Ugo Fiore
Comput. Secur.1
2010 Towards a federated Metropolitan Area Grid environment: The SCoPE network-aware infrastructure
Francesco Palmieri 0002, Silvio Pardi
Future Gener. Comput. Syst.1
2009 SimulNet: a wavelength-routed optical network simulation framework
abstract
Simulation seems to be the best available alternative to the deployment of expensive and complex testbed infrastructures for the activities of testing, validating and evaluating optical network control protocols and algorithms. In this paper we present SimulNet, a specialized optical network simulation environment providing the foundation for the study and analysis of the key control plane characteristics of wavelength-routed networks. Such an environment would provide researchers with an open framework for easily exploring the evolving characteristics of WDM-routed technologies which includes developing new protocol suites or performing rapid evaluation and easier comparison of results across research efforts.
Francesco Palmieri 0002, Ugo Fiore, Sergio Ricciardi
ISCC1
2009 A nonlinear, recurrence-based approach to traffic classification
Francesco Palmieri 0002, Ugo Fiore
Comput. Networks1
2009 Providing true end-to-end security in converged voice over IP infrastructures
Francesco Palmieri 0002, Ugo Fiore
Comput. Secur.1
2009 Network-aware scheduling for real-time execution support in data-intensive optical Grids
Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2008 Network-Aware Replica Optimization in the SCoPE Grid Infrastructure
Francesco Palmieri 0002, Silvio Pardi
ICCSA (2)1
2008 Containing large-scale worm spreading in the Internet by cooperative distribution of traffic filtering policies
Francesco Palmieri 0002, Ugo Fiore
Comput. Secur.1
2006 Audit-Based Access Control in Nomadic Wireless Environments
Francesco Palmieri 0002, Ugo Fiore
ICCSA (3)1
2006 GMPLS-based service differentiation for scalable QoS support in all-optical Grid applications
Francesco Palmieri 0002
Future Gener. Comput. Syst.1
2005 Securing the MPLS Control Plane
Francesco Palmieri 0002, Ugo Fiore
HPCC1
2005 An MPLS-based architecture for scalable QoS and traffic engineering in converged multiservice mobile IP networks
Francesco Palmieri 0002
Comput. Networks1
2004 A Scalable PKI for Secure Routing in the Internet
Francesco Palmieri 0002
ICCSA (1)1
2003 VPN scalability over high performance backbones Evaluating MPLS VPN against traditional approaches
abstract
The rapid growth of the Internet and the widespread deployment of networks built around the Internet protocol suite are creating a demand for new capabilities in IP networks. The IP-based virtual private network (VPN) technology is rapidly becoming the foundation for the delivery of future Internet services, and many service providers are offering value-added applications on top of their VPN transport networks. Two unique and complementary architectures based on traditional industry standard encrypted tunnels (IPSec) and still developing multiprotocol label switching (MPLS) technologies are emerging to form the predominant framework for delivery of high performance VPN services. We analyzed the strengths and the weaknesses of both the approaches, and compared their performance and scalability features by carefully testing them against the requirements of the future optical high performance backbones. Our technical considerations and experimental results strongly emphasized the better scalability and reliability of the MPLS/BGP model that seems to be the most promising approach for the provisioning of VPN services on the future Giga-speed optical backbones.
Francesco Palmieri 0002
ISCC1