VLDB 2026 Research / reviewers in the wild / expert
Francesco Buccafurri
dblp:90/3368
· DBLP profile ↗
90ranked-venue papers
81as first author
26since 2021 · last 2026
0000-0003-0448-8464ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 28 · 28 first-author · 2 since 2021Security and privacy · 25 · 20 first-author · 8 since 2021Artificial intelligence and machine learning · 19 · 17 first-author · 1 since 2021Software engineering, systems software and programming languages · 10 · 10 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 7 · 5 first-author · 3 since 2021Theory of computation · 7 · 7 first-authorApplied, interdisciplinary, general and emerging computing · 7 · 7 first-author · 4 since 2021Computer networks · 6 · 6 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CallTrust: A federated system for call authentication in telephony networks
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Carmen Licciardi |
J. Inf. Secur. Appl. | 1 |
| 2025 | MQTT-E: E2E encryption in MQTT via proxy re-encryption avoiding broker overloadingabstractA smart traffic monitoring system in smart city surveillance requires publisher and subscriber MQTT-enabled vehicles to share sensitive vehicle and route data with semi-trusted RSU nodes as brokers. To ensure end-to-end confidentiality, we propose the use of an RSU broker as a proxy to perform re-encryption of the exchanged messages between publisher and subscriber vehicles. The RSU brokers are implemented as serverless edge devices with the proxy re-encryption functions designed as function-as-a-service. In peak traffic scenarios, the RSU proxy brokers can become overloaded and drop the re-encryption operations. Additionally, a malicious actor can send counterfeit re-encryption requests to overload the brokers leading to Denial-of-Service attacks. In this paper, we propose a novel solution to mitigate DoS attacks by balancing the re-encryption functions from overloaded brokers. This problem is modeled as an online optimization problem , solved using a greedy heuristic approach, and compared with a baseline approach. The objective function is to reallocate the minimum number of clients when brokers are overloaded since this operation brings additional overhead for clients. Our experimental analysis shows that the greedy approach manages to move up to 5 times fewer clients than the baseline approach, depending on the scenario considered. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Anusha Vangala |
Ad Hoc Networks | 1 |
| 2025 | Extending Tor to achieve recipient anonymityabstractAbstract Tor is a well-known routing protocol implementing the Onion multi-layered encryption to achieve communication anonymity. Among other possible attacks, Tor is vulnerable to passive attacks based on the compromise of multiple nodes, allowing the adversary to observe the traffic flow and then identify the relationship between sender and recipient. Relationship anonymity, in every threat model, can be reached by achieving at least one between sender and recipient anonymity. Tor implements the onion-service mechanism to offer recipient anonymity. However, it does not protect against a global adversary, that monitors the traffic exchanged in the network. The idea of this paper is to achieve such protection by relying on the collaboration of k Tor relays to hide the actual recipient within an anonymity set of relays. Our approach also includes the exchange of cover traffic among the collaborating Tor relays. We implement this approach by first proposing a modification to Tor (called L-Tor) that preserves the linear circuits as in standard Tor. Then, we propose B-Tor, extending Tor via tree-like circuits. Our analysis shows that using linear circuits (as in L-Tor) would not lead to advantageous results due to the resulting high latency. Instead, we show that B-Tor achieves protection against global adversaries while preserving low-latency applications. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
Cybersecur. | 1 |
| 2025 | Hiding identities of MQTT devices against a global network adversaryabstractIn the IoT context, there is an increasing demand for privacy. Indeed, IoT devices can collect and transmit sensitive data that can reveal users’ behavior and preferences to third parties. Making the identity of devices anonymous is one of the privacy challenges. In this paper, we address this problem by referring to the MQTT protocol. MQTT is a widely adopted publish-subscribe model tailored for low-end devices. In particular, we propose an approach to achieve anonymity guarantees in MQTT against a global network adversary. Our approach takes inspiration from mixnet-based anonymous protocols, but it is appropriately tailored for MQTT clients. Indeed, our solution has the following features: (1) it is lightweight for MQTT clients, (2) it satisfies the decoupling principles, and (3) it guarantees that subscribers can join and leave the system at any time. By analyzing the security of the proposed approach, we demonstrate that the considered adversary, via known attacks, is unable to reduce its uncertainty in identifying the originator (publisher) or the recipient (subscriber) of a message. We conducted an experimental campaign showing that the strong benefits of anonymity provided by our solution come at the cost of latency with respect to state of the art which offers lower anonymity guarantees. However, this price is acceptable for the amount of bytes typically sent by IoT devices. Sara Lazzaro, Vincenzo De Angelis, Francesco Buccafurri |
EURASIP J. Inf. Secur. | 3 |
| 2025 | A black-box assessment of authentication and reliability in consumer IoT devices
Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri |
Pervasive Mob. Comput. | 4 |
| 2024 | A Framework for Secure Internet of Things ApplicationsabstractMQTT is the de facto standard protocol for Internet of Things (IoT) devices. It is a messaging protocol based on lightweight publish-subscribe architecture, tailored specifically for devices with limited computational capabilities. Being a lightweight protocol, it lacks security and privacy features. The OASIS standard suggests some mechanisms to enhance the MQTT protocol. Therefore it is the implementer’s responsibility to include these mechanisms as part of their design. In this paper, we identify three main missing features in MQTT, which are: (1) the presence of weak authentication procedures, (2) the lack of end-to-end security mechanisms, and (3) the lack of privacy mechanisms. Therefore, we propose to fill these gaps with three solutions from the literature, all leveraging the standard MQTT primitives. Finally, we propose a comprehensive framework showing how to combine the three above solutions with the security guidelines presented in the OASIS standard. Francesco Buccafurri, Sara Lazzaro |
CoDIT | 1 |
| 2024 | Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT DevicesabstractConsumer Internet of Things (IoT) devices often leverage the local network to communicate with the corresponding companion app or other devices. This has benefits in terms of efficiency since it offloads the cloud. ENISA and NIST security guidelines underscore the importance of enabling default local communication for safety and reliability. Indeed, an IoT device should continue to function in case the cloud connection is not available. While the security of cloud-device connections is typically strengthened through the usage of standard protocols, local connectivity security is frequently overlooked. Neglecting the security of local communication opens doors to various threats, including replay attacks. In this paper, we investigate this class of attacks by designing a systematic methodology for automatically testing IoT devices vulnerability to replay attacks. Specifically, we propose a tool, named REPLIoT, able to test whether a replay attack is successful or not, without prior knowledge of the target devices. We perform thousands of automated experiments using popular commercial devices spanning various vendors and categories. Notably, our study reveals that among these devices, 51% of them do not support local connectivity, thus they are not compliant with the reliability and safety requirements of the ENISA/NIST guidelines. We find that 75% of the remaining devices are vulnerable to replay attacks with REPLIoT having a detection accuracy of 0.98-1. Finally, we investigate the possible causes of this vulnerability, discussing possible mitigation strategies. Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri |
PerCom | 4 |
| 2024 | K-Anonymous Payments in Pseudonymous BlockchainsabstractLinkability of transactions is a serious threat to cryptocurrency payment anonymity. In fact, in pseudonymous blockchains, payments are not considered to be effectively anonymous. Blockchains such as Monero or Zcash aim to prevent transaction linkability by using complex cryptographic mechanisms. Therefore, they are considered anonymous blockchains. However, the recent literature has proven that, in a threat model in which the adversary is able to monitor network traffic, transaction linkability can be achieved even in anonymous blockchains. In this paper, we propose a solution that allows k-anonymous payments also in the above threat model, thus overcoming the privacy problem that plagues blockchains. The solution is inspired by overlay-routing approaches used in the context of anonymous communication networks when the global network adversary is allowed. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
WiMob | 1 |
| 2024 | How can the holder trust the verifier? A CP-ABPRE-based solution to control the access to claims in a Self-Sovereign-Identity scenarioabstractThe interest in Self-Sovereign Identity (SSI) in research, industry, and governments is rapidly increasing. SSI is a paradigm where users hold their identity and credentials issued by authorized entities. SSI is revolutionizing the concept of digital identity enabling the definition of a trust framework wherein a service provider (verifier) validates the claims presented by a user (holder) for accessing services. However, current SSI solutions primarily focus on the presentation and verification of claims, overlooking a dual aspect: ensuring that the verifier is authorized to access the holder's claims. Addressing this gap, this paper introduces an innovative SSI-based solution that integrates decentralized wallets with Ciphertext-Policy Attribute-Based Proxy Re-Encryption (CP-ABPRE). This combination effectively addresses the challenge of verifier authorization. Our solution, implemented on the Ethereum platform, enhances accountability by notarizing key operations through a smart contract. The paper also offers a prototype demonstrating the practicality of the proposed approach. Furthermore, it provides an extensive evaluation of the solution's performance, emphasizing its feasibility and efficiency in real-world applications. Francesco Buccafurri, Vincenzo De Angelis, Roberto Nardone |
Blockchain Res. Appl. | 1 |
| 2024 | A hierarchical distributed trusted location service achieving location k-anonymity against the global observerabstractAs widely known in the literature, location-based services can seriously threaten users’ privacy. Privacy-aware location-based services can be obtained by protecting the user’s identity, so that queries cannot be linked with users. A way to do this is to place a trusted third party, called Location Trusted Service, between the user and the service provider, with the role of mediating the queries coming from the users and proxying them to the provider. Before proxying the query, the Location Trusted Service builds a cloaking area that includes a sufficient number of users such that it can represent an anonymity set. This way, the identity of the user is protected against an untrusted service provider. Unfortunately, in wide-area scenarios, a centralized location-trusted service might represent a serious threat to security and privacy because the service represents a single point of failure that manages very critical and massive information. Moreover, privacy protection also against a global adversary capable to monitor the whole traffic, would result in an excessive amount of cover traffic in the network (being cover traffic necessary in this threat model). To overcome the above limitations we propose a hierarchical Location Trusted Service, whose implementation benefits from the edge–cloud paradigm. In our proposal, the territory is organized in hierarchical zones possibly managed by different autonomous organizations. Organizations that manage higher zones are involved when lower-level organizations are not able to satisfy the requests of the users. As only the lowest-level services manage exact location data, while the higher ones operate only on aggregate values, the risk associated with the single point of failure of the centralized solution is drastically reduced. Moreover, leveraging the edge–cloud implementation of the system, network traffic is better confined to the edge of the network, making the protection against the global observer feasible. A nice feature of our method is that it is parametric with respect to any existing cloaking area construction technique. However, as our method, for non-local queries, operates on aggregate data, a certain degree of approximation is introduced. To validate our proposal, we conducted an experimental campaign on a real-life map by applying our method on top of well-known cloaking area construction technique called Casper. The results turned out to be positive. For a wide range of sizes of the anonymity set, the approximation (expressed by the metric called effectiveness) is less than 10%. On the other hand, concerning the network performance, we have observed an improvement in latency and throughput ranging from 20% to 170% (depending on the size of the anonymity set). In the highest density distribution, we achieve a 66% saving in overall (non-local) traffic compared to the centralized approach. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
Comput. Networks | 1 |
| 2024 | Enforcing security policies on interacting authentication systemsabstractSecurity policies of authentication systems are a crucial factor in mitigating the risk of impersonation, which is often the first stage of advanced persistent threats. Online authentication systems may often interact with each other, due to various mechanisms, such as account recovery or federated authentication. This leads to an implicit extension of the security policies of an authentication system with policies over which the system has no control. As a result, an authentication system that adopts very strong security policies can be unexpectedly weak. This paper deals with the above problem, which affects most real-world online authentication systems. The paper proposes a theoretical framework that formalizes authentication policies and interactions among authentication systems, together with a protocol that prevents, whenever an interaction is established or updated, the security issues described above. An SSI-based implementation of the proposed protocol is presented as well. • Online authentication systems may interact with each other (e.g., for account recovery, federated authentication, etc.). • Interaction between authentication systems may be adopted to bypass strong security policies of authentication systems. • Our work proposes a framework that formalizes authentication policies and interactions among authentication systems. • We provide an SSI-based protocol for the establishment and the update of the interactions between authentication systems. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Andrea Pugliese 0001 |
Comput. Secur. | 1 |
| 2024 | MQTT-I: Achieving End-to-End Data Flow Integrity in MQTTabstractMQTT has become the de facto standard in the IoT. Although standard MQTT lacks built-in security features, several proposals have been made to address this gap. Unfortunately, no existing proposal aims to offer end-to-end data flow integrity in the threat model of untrusted broker. Consider that, the broker has a privileged role, since it is in the middle of communication between publishers and subscribers. Our paper attempts to bridge this gap by introducing a new protocol called MQTT-I, which achieves end-to-end data flow integrity. Our solution is inspired by approaches based on Merkle Hash Trees, commonly used in the context of outsourced data to guarantee data integrity. Our solution aligns with the specific nature of MQTT, in which: (1) publishers and subscribers dynamically join and leave the system, (2) the decoupling principle holds, meaning that publishers and subscribers do not establish any form of agreement, and (3) data, whose integrity should be protected, are multi-topic streams. Moreover, the proposed solution allows us to find the right balance between performance and security. We perform both theoretical and experimental analysis to demonstrate that the introduced security features come with an acceptable overhead in terms of computational and energy cost. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | A Greedy Method for Coverage Path Planning of Autonomous Heterogeneous UAVsabstractCoverage Path Planning (CPP) is a well-known problem which objective is to find an optimal plan for a fleet of UAVs covering a certain area of interest in the shortest overall time. CPP has a practical impact even in its static formulation, due to the growing interest in UAVs and their numerous applications such as surveillance, terrain coverage, mapping, natural disaster tracking, transport, and others. Unfortunately, CPP is NP-hard, so that it is computationally infeasible to obtain an exact solution for a large number of UAVs and regions. Different approaches are available in the literature to face the above problem. In this paper, we propose a novel approach working in the case of autonomous heterogeneous UAVs, based on a greedy technique. The method appears promising for its nice features of computational efficiency and potential adaptivity in the case of dynamic settings. Francesco Buccafurri, Francesca Scoleri |
CoDIT | 1 |
| 2023 | Adapting P2P Mixnets to Provide Anonymity for Uplink-Intensive Applications
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
SECRYPT | 1 |
| 2023 | MQTT-A: A Broker-Bridging P2P Architecture to Achieve Anonymity in MQTTabstractThe demand for privacy in the current digital era is continuously growing. This is particularly true in the context of IoT, in which huge amounts of data are handled. Communication anonymity is a fundamental requirement when high privacy levels should be guaranteed. On the other hand, very little attention has been devoted to this problem in the past scientific literature, when referring to MQTT, which is the de-facto standard for IoT communication. In this paper, we try to cover this gap. Specifically, we propose a new protocol, called MQTT-A, which extends the MQTT bridging mechanism to support the anonymity of both publishers and subscribers. This task is accomplished through the P2P collaboration of intermediate bridge brokers, which forward the requests of clients so that the final broker cannot understand the actual source/destination. Moreover, an anonymity-preserving topic discovery mechanism is provided, which allows clients to discover available topics and associated brokers, preventing client identification. Importantly, all the MQTT-A messages are exchanged by leveraging standard MQTT primitives and the bridging mechanism natively offered by MQTT. This allows us not to require changes in the standard MQTT infrastructure. To validate the performance of our solution, we performed a deep experimental campaign by deploying the bridge brokers on cloud platforms in various countries of the world. The experimental validation shows that, the price of latency we have to pay because of the trade-off with anonymity is quite reasonable. Moreover, no significant impact on goodput occurs in the case of good network conditions. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
IEEE Internet Things J. | 1 |
| 2023 | Enabling anonymized open-data linkage by authorized partiesabstractNowadays, many entities collect useful information about users, in order to implement the provided service, and publish them as open data. To prevent privacy leakage, data are often anonymized prior to publication. Unfortunately, anonymization strongly hinders data linkage, which can be very useful for analysis purposes instead. In this paper, we deal with the above problem, by proposing a technique that enriches anonymized open data with pseudo-random labels. This way, some authorized parties (i.e., the analysts) are enabled to link data regarding the same user coming from different sources. Instead, for non-authorized people, labels do not carry any information, thus not introducing additional privacy threats with respect to original open data. In other words, our solution allows us to recover linkage capabilities on anonymized open data, thus enabling more powerful data exploitation. Indeed, the linked open data paradigm, involving both the public sector and business, is recognized as one of the most promising approaches for boosting societal growth. To offer a concrete solution, we refer to an existing open-data standard and we implement the protocol through a SAML-based SSO framework adhering to the eIDAS regulation. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
J. Inf. Secur. Appl. | 1 |
| 2022 | The Ginger: Another Spice to Hinder Attacks on Password Files
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
WEBIST | 1 |
| 2022 | An integrity-preserving technique for range queries over data streams in two-tier sensor networks
Francesco Buccafurri, Vincenzo De Angelis, Gianluca Lax |
Comput. Networks | 1 |
| 2022 | A centralized contact-tracing protocol for the COVID-19 pandemic
Francesco Buccafurri, Vincenzo De Angelis, Cecilia Labrini |
Inf. Sci. | 1 |
| 2021 | Extending Routes in Tor to Achieve Recipient Anonymity against the Global AdversaryabstractTor is a famous routing overlay network based on the Onion multi-layered encryption to support communication anonymity in a threat model in which some network nodes are malicious. However, Tor does not provide any protection against the global passive adversary. In this threat model, an idea to obtain recipient anonymity, which is enough to have relationship anonymity, is to hide the recipient among a sufficiently large anonymity set. However, this would lead to high latency both in the set-up phase (which has a quadratic cost in the number of involved nodes) and in the successive communication. In this paper, we propose a way to arrange a Tor circuit with a tree-like topology, in which the anonymity set consists of all its nodes, whereas set-up and communication latency depends on the number of the sole branch nodes (which is a small fraction of all the nodes). Basically, the cost goes down from quadratic to linear. Anonymity is obtained by applying a broadcast-based technique for the forward message, and cover traffic (generated by the terminal-chain nodes) plus mixing over branch nodes, for the response. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
CW | 1 |
| 2021 | A Privacy-Preserving Protocol for Proximity-Based Services in Social NetworksabstractA number of real-life social networks provide the users with proximity-based services. This feature exposes to seri-ous privacy threats, because it could allow massive tracking from an honest-but-curious provider. Whilst proximity-based services have been deeply studied in the literature in a general setting, no solution (to the best of our knowledge) has been provided to the problem of delivering privacy-preserving proximity-based services entirely within existing social networks. The problem is not trivial, because a social network provider can play as a global passive adversary, monitoring the flow of all the messages exchanged in the network. Therefore, to allow proximity testing between Alice and Bob not requiring that they reveal their position to the social network provider is not enough. Indeed, even the fact that proximity testing is performed between Alice and Bob (independently of the result) is a serious privacy leakage. In this paper, we provide a solution preventing also this privacy leak, giving thus a concrete way to implement privacy-preserving proximity-based services in social networks. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
GLOBECOM | 1 |
| 2021 | A game theory-based approach to discourage fake reviewsabstractThe introduction of a review system in e-commerce platforms results in an effective business model. The effects of positive/negative reviews on the success of a product are well studied in the literature. Therefore, for the vendors, it is crucial to obtain positive reviews of their products. This fact opens fraudulent scenarios. Indeed, some vendors can pay an incentive to the buyers to obtain, in exchange, a fake positive review. This fake-review system (FRS) is so widespread that vendors rely on ad-hoc companies that, through intermediaries, find buyers available to release fake reviews. In this paper, we propose a game-theory-based strategy to discourage the above fraudulent business model, and an effective way to implement this strategy leveraging an Ethereum smart contract. Specifically, the contribution of the paper is two-fold. First, we formalize the current business model as a sequential game, and we identify sufficient conditions making FRS advantageous. Second, we propose to introduce in the review system a new mechanism, thanks to which, the corresponding sequential game requires conditions necessary to make advantageous FRS that are strictly less convenient than the previous ones. We implemented the solution and evaluate the cost of the smart contract execution. Vincenzo De Angelis, Francesco Buccafurri |
KES | 2 |
| 2021 | A Distributed Location Trusted Service Achieving k-Anonymity against the Global AdversaryabstractWhen location-based services (LBS) are delivered, location data should be protected against honest-but-curious LBS providers, them being quasi-identifiers. One of the existing approaches to achieving this goal is location k-anonymity, which leverages the presence of a trusted party, called location trusted service (LTS), playing the role of anonymizer. A drawback of this approach is that the location trusted service is a single point of failure and traces all the users. Moreover, the protection is completely nullified if a global passive adversary is allowed, able to monitor the flow of messages, as the source of the query can be identified despite location k-anonymity. In this paper, we propose a distributed and hierarchical LTS model, overcoming both the above drawbacks. Moreover, position notification is used as cover traffic to hide queries and multicast is minimally adopted to hide responses, to keep k-anonymity also against the global adversary, thus enabling the possibility that LBS are delivered within social networks. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
MDM | 1 |
| 2021 | Anonymous Short Communications over Social Networks
Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
SecureComm (2) | 1 |
| 2021 | Hardening Trust Models against Slandering Attacks in Relayed Content Delivery ServicesabstractThere are a number of application contexts in which services are delivered by a given provider to some clients through other relay clients in a collaborative fashion. This is, for example, the case of sensor networks, vehicular networks, D2D, and so on. In this case, a security problem arises. Indeed, when a service is relayed by a client, it is not sure that it is relayed correctly. Therefore, the final client could be deceived if malicious relay clients exist. The classical way to contrast this problem is to use a trust mechanism, managed by the provider, based on the feedback returned by the clients. Thanks to this mechanism, the trust of malicious relay clients can be decreased, then reducing (even cancelling) the negative effects of these clients in the community. The trust mechanisms of this type often suffer from weakness against slandering attacks. Dishonest final clients can fraudulently decrease the trust of relay clients, by reporting a false feedback. In this paper, we propose a general approach to fortify the trust mechanism against this kind of attacks. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
WiMob | 1 |
| 2021 | WIP: An Onion-Based Routing Protocol Strengthening AnonymityabstractAnonymous Communication Networks (ACNs) are networks in which, beyond data confidentiality, also traffic flow confidentiality is provided. The most popular routing approach for ACNs also used in practice is Onion. Onion is based on multiple encryption wrapping combined with the proxy mechanism (relay nodes). However, it offers neither sender anonymity nor recipient anonymity in a global passive adversary model, simply because the adversary can observe (at the first relay node) the traffic coming from the sender, and (at the last relay node) the traffic delivered to the recipient. This may also cause a loss of relationship anonymity if timing attacks are performed. This paper presents Onion-Ring, a routing protocol that improves anonymity of Onion in the global adversary model, by achieving sender anonymity and recipient anonymity, and thus relationship anonymity. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
WOWMOM | 1 |
| 2020 | A Privacy-Preserving Solution for Proximity Tracing Avoiding Identifier ExchangingabstractDigital contact tracing is one of the actions useful, in combination with other measures, to manage an epidemic diffusion of an infectious disease in an after-lock-down phase. This is a very timely issue, due to the pandemic of COVID19 we are unfortunately living. Apps for contact tracing aim to detect proximity of users and to evaluate the related risk in terms of possible contagious. Existing approaches leverage BLE or GPS, or their combination, even though the prevailing approach is BLE-based and relies on a decentralized model requiring the mutual exchange of ephemeral identifiers among users' smartphones. Unfortunately, a number of security and privacy concerns exist in this kind of solutions, mainly due to the exchange of identifiers, while GPS-based solutions (inherently centralized) may suffer from threats concerning massive surveillance. In this paper, we propose a solution leveraging GPS to detect proximity, and BLE only to improve accuracy, with no exchange of identifiers. Unlike related existing solutions, no complex cryptographic mechanism is adopted, while ensuring that the server does not learn anything about locations of users. Francesco Buccafurri, Vincenzo De Angelis, Cecilia Labrini |
CW | 1 |
| 2020 | A Privacy-Preserving Localization Service for Assisted Living FacilitiesabstractIn this paper, we propose a novel localization service to monitor the position of residents in assisted living facilities. The service supports a configurable balancing between precision and privacy, in such a way that the right of the residents to move freely in the environment in which they live without being tracked is preserved. However, in case of need, they can always be quickly localized. To do this, we implement, on top of an RFID-based architecture, a probabilistic model guaranteeing that the probability of identifying a person in a given (sensitive) place is at most k-1, where k represents the required privacy level. This is obtained by ensuring that the EPC sent by RFID tags is not an identifier, but is equal to that of at least other k - 1 people, each afferent to a different reader. We show that our method reaches the goal, resisting also attacks aimed at breaking privacy on the basis of humans' movement models. Importantly, privacy is guaranteed against both misuse of the administrator and client-side eavesdropping attacks. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
IEEE Trans. Serv. Comput. | 1 |
| 2019 | An Attribute-Based Privacy-Preserving Ethereum Solution for Service Delivery with Accountability RequirementsabstractThe main benefit of smart contracts over Ethereum is that different parties with conflicting interests can exchange value without trusting each other. As a matter of fact, solutions in which service delivery is regulated by smart contracts are proliferating. Sometimes, services can be negotiated and delivered only on the basis of some attributes, without disclosing the identity of the customer to the service supplier. However, accountability is still required, so that, in case of need, the identity of the customer should be linked to the service delivered and communicated to the appropriate parties. In this paper, we propose a practical solution to the above problem that integrates the features of Ethereum with a (Ciphertext-Policy) Attribute-Based Encryption scheme. To show the effectiveness of our proposal, we instantiate the general model to a significant use case. Francesco Buccafurri, Vincenzo De Angelis, Gianluca Lax, Lorenzo Musarella, Antonia Russo |
ARES | 1 |
| 2019 | Enabling propagation in web of trust by EthereumabstractWeb of Trust offers a way to bind identities with the corresponding public keys. It relies on a distributed architecture, where each user could play the role of certificate signer. With the widespread diffusion of social networks, the trust propagation is a matter of growing interest. This paper proposes an approach enabling the propagation in Web of Trust by means of Ethereum. The usage of Ethereum eliminates the necessity of single-organization trusted services, which is, in general, not realistic. Although the information stored on Ethereum is public, the privacy of users is protected because trust chains involve only Ethereum addresses and strong measures are implemented to contrast their malicious de-anonymization. The approach relies on the usage of a smart contract for storing the status of certificate signatures and to manage revocations. When a user u wants to trust another user v, the smart contract checks the presence of trust chains originating from root nodes of u. Francesco Buccafurri, Lorenzo Musarella, Roberto Nardone |
IDEAS | 1 |
| 2019 | Self-sovereign Management of Privacy Consensus using BlockchainabstractIn this paper, we propose a solution implementing a self-sovereign approach to manage privacy consensus in a open domain. The idea is allowing the user to set her policies in a unique way, in such a way that she keeps the full control on her personal data. The goal is achieved by combining blockchain with Attribute-Based Encryption and Proxy Re-encryption. Blockchain is also used to implement the notarization of the critical actions to obtain accountability and non-repudiation. Francesco Buccafurri, Vincenzo De Angelis |
WEBIST | 1 |
| 2019 | A Novel Query Language for Data Extraction from Social NetworksabstractOnline Social Networks (OSNs) represent an important source of information since they manage a huge amount of data that can be used in many different contexts. Moreover, many people create and manage more than one social profile in the different available OSNs. The combination and the extraction of the set of data from contained in OSNs can produce a huge amount of additional information regarding both a single person and the overall society. Consequently, the data extraction from multiple social networks is a topic of growing interest. There are many techniques and technologies for data extraction from a single OSN, but there is a lack of simple query languages which can be used by programmers to retrieve data, correlate resources and integrate results from multiple OSNs. This work describes a novel query language for data extraction from multiple OSNs and the related supporting tool to edit and validate queries. With respect to existing languages, the designed language is general enough to include the variety of resources managed by the different OSNs. Moreover, thanks to the support of the editing environment, the language syntax can be customised by programmers to express searching criteria that are specific for a social network. Francesco Buccafurri, Gianluca Lax, Lorenzo Musarella, Roberto Nardone |
WEBIST | 1 |
| 2017 | Overcoming Limits of Blockchain for IoT ApplicationsabstractBlockchain technology allows the implementation of a public ledger securely recording transactions among peers without the need of trusted third parties. For both researchers and industry IoT appears a domain in which there would be extraordinary benefits if the features of Blockchain can be exploited. Indeed, the possibility that IoT devices participate in public shared transactions enables a lot of challenging applications. However, there are some aspects that may limit the use of Blockchain in IoT. These are mainly related to the low computational power and storage capabilities of IoT devices. In this paper, we propose an alternative way to implement a public ledger overcoming the above drawbacks, thus appearing more suitable to IoT applications. The proposed protocol leverages the popular social network Twitter and works by building a meshed chain of tweets to ensure transaction security. Importantly, Twitter does not play neither the role of trusted third party nor the role of ledger provider. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ARES | 1 |
| 2017 | Contrasting False Identities in Social Networks by Trust Chains and Biometric ReinforcementabstractFake identities and identity theft are issues whose relevance is increasing in the social network domain. This paper deals with this problem by proposing an innovative approach which combines a collaborative mechanism implementing a trust graph with keystroke-dynamic-recognition techniques to trust identities. The trust of each node is computed on the basis of neighborhood recognition and behavioral biometric support. The model leverages the word of mouth propagation and a settable degree of redundancy to obtain robustness. Experimental results show the benefit of the proposed solution even if attack nodes are present in the social network. Francesco Buccafurri, Gianluca Lax, Denis Migdal, Serena Nicolazzo, Antonino Nocera, Christophe Rosenberger |
CW | 1 |
| 2017 | Tweetchain: An Alternative to Blockchain for Crowd-Based Applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ICWE | 1 |
| 2016 | Range Query Integrity in Cloud Data Streams with Efficient Insertion
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
CANS | 1 |
| 2016 | A New Approach for Electronic SignatureabstractThere are many application contexts in which guaranteeing authenticity and integrity of documents is essential.In these cases, the typical solution relies on digital signature, which is based on the use of a PKI infrastructure and suitable devices (smart card or token USB).For several reasons, including certificate and device cost, many countries, such as the United States, the European Union, India, Brazil and Australia, have introduced the possibility to use simple generic electronic signature, which is less secure but reduces the drawbacks of digital signature.In this paper, we propose a new type of electronic signature that is based on the use of social networks.We formalize the proposal in a generic scenario and then, show a possible implementation on Twitter.Our proposal is proved to be secure, cheap and simple to adopt. Gianluca Lax, Francesco Buccafurri, Serena Nicolazzo, Antonino Nocera, Lidia Fotia |
ICISSP | 2 |
| 2016 | Efficient Proxy Signature Scheme from Pairings
Francesco Buccafurri, Rajeev Anand Sahu, Vishal Saraswat |
SECRYPT | 1 |
| 2016 | Interest Assortativity in TwitterabstractAssortativity is the preference for a person to relate to others who are someway similar.This property has been widely studied in real-life social networks in the past and, more recently, great attention is devoted to study various forms of assortativity also in online social networks, being aware that it does not suffice to apply past scientific results obtained in the domain of real-life social networks.One of the aspects not yet analyzed in online social networks is interest assortativity, that is the preference for people to share the same interest (e.g., sport, music) with their friends.In this paper, we study this form of assortativity on Twitter, one of the most popular online social networks.After the introduction of the background theoretical model, we analyze Twitter, discovering that users clearly show interest assortativity.Beside the theoretical assessment, our result leads to identify a number of interesting possible applications. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
WEBIST (1) | 1 |
| 2016 | Analysis-preserving protection of user privacy against information leakage of social-network Likes
Francesco Buccafurri, Lidia Fotia, Gianluca Lax, Vishal Saraswat |
Inf. Sci. | 1 |
| 2016 | A model to support design and development of multiple-social-network applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
Inf. Sci. | 1 |
| 2015 | A Model Implementing Certified Reputation and Its Application to TripAdvisorabstractMany real-life reputation models suffer from classical drawbacks making the systems where they are used vulnerable to users' misbehavior. TripAdvisor is a good example of this problem. Indeed, despite its popularity, the weakness of its reputation model is resulting in loss of credibility and growth of legal disputes. In this paper, we propose a reputation model abstractly considering service providers, users and feedbacks, and implementing the theoretical notion of certified reputation to concretely define a strategy to normalize feedback scores towards reliable values. We apply the model to the case of TripAdvisor, by proposing a solution to improve its dependability not increasing invasiveness nor reducing usability of the system. Moreover, it fully guarantees backward compatibility. In the context of project activities, we are in progress to fully implement the system and validate it on real-life data. Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
ARES | 1 |
| 2015 | Practical and Secure Integrated PKE+PEKS with Keyword PrivacyabstractPublic-key encryption with keyword search (PEKS) schemes are useful to delegate searching capabilities on encrypted data to a third party, who does not hold the entire secret key, but only an appropriate token which allows searching operations but preserves data privacy. We propose an efficient and practical integrated public-key encryption (PKE) and public-key encryption with keyword search (PEKS) scheme (PKE+PEKS) which we prove to be secure in the strongest security notion for PKE+PEKS schemes. In particular, we provide a unified security proof of its joint CCA-security in standard model. The security of our scheme relies on Symmetric eXternal Diffie-Hellman (SXDH) assumption which is a much simpler and more standard hardness assumption than the ones used in most of the comparable schemes. Ours is the first construction to use asymmetric pairings which enable an extremely fast implementation useful for practical applications. Finally we compare our scheme with other proposed integrated PKE+PEKS schemes and provide a relative analysis of its efficiency. Francesco Buccafurri, Gianluca Lax, Rajeev Anand Sahu, Vishal Saraswat |
SECRYPT | 1 |
| 2015 | An analytical processing approach to supporting cyber security compliance assessmentabstractCompliance analysis is an important step for the security management process of systems. It aims at both increasing service quality and reducing service vulnerabilities by exploiting security mechanisms able to improve the fulfillment of requirements whose failure may cause direct and indirect costs, related to the existence of missed normative provisions, risk of loss of certifications, and increased probability and impact of security incidents. Due to the increasing in system complexity there are hundreds of requirements that must be observed simultaneously and satisfied. As a consequence, the need for innovative approaches centered on effective solutions able to support the evaluation and the validation of requirements and constraints over the time is today greater than ever. In this context, the paper proposes a method for supporting the compliance assessment of services, in respect of norms and regulations, exploitable both in design phase or during the operation of existing services supported by (semi-)automatic tools. The effectiveness of the method is then tested through a case study taken from the experience of the Computer Emergency Response Team (CERT) of Poste Italiane, concerning the compliance assessment of an Electronic Payment Service by credit card. Francesco Buccafurri, Lidia Fotia, Angelo Furfaro, Alfredo Garro, Matteo Giacalone, Andrea Tundis |
SIN | 1 |
| 2015 | Accountability-Preserving Anonymous Delivery of Cloud Services
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera |
TrustBus | 1 |
| 2015 | A new form of assortativity in online social networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera |
Int. J. Hum. Comput. Stud. | 1 |
| 2015 | Discovering missing me edges across social networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Inf. Sci. | 1 |
| 2015 | A system for extracting structural information from Social Network accountsabstractThe social network phenomenon involves hundreds of millions of people every day. This enormous volume of activity results in a huge source of information that can be valuable in many fields, for both research and application purposes. The relevance of this information strongly depends on the evolution occurring in the social Web, in which interaction among different social networks and their cross-relationships are becoming progressively more important. This, in fact, represents the basis of an emergent scenario called Social Internetworking Scenario. However, efficiently accessing and fruitfully querying this huge information source is not easy, because no tool to support applications needing a massive utilization of cross-social-network data exists. In this paper, we fill this gap by proposing Social Network Account Knowledge Extractor (SNAKE), a system supporting the extraction of structural data from a social network account. SNAKE is implemented in such a way as to be easily integrated in any social-network-based application. To show the practical relevance of our proposal, we present our experience gained in three possible real-life applications strongly relying on information provided by SNAKE. Copyright © 2014 John Wiley & Sons, Ltd. Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Softw. Pract. Exp. | 1 |
| 2014 | Driving Global Team Formation in Social Networks to Obtain Diversity
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera, Domenico Ursino |
ICWE | 1 |
| 2014 | A Trust-Based Approach to Clustering Agents on the Basis of Their Expertise
Francesco Buccafurri, Antonello Comi, Gianluca Lax, Domenico Rosaci |
KES-AMSTA | 1 |
| 2014 | Trust-Based Intrusion Tolerant Routing in Wireless Sensor Networks
Francesco Buccafurri, Luigi Coppolino, Salvatore D'Antonio, Alessia Garofalo, Gianluca Lax, Antonino Nocera, Luigi Romano |
SAFECOMP | 1 |
| 2014 | A Novel Pseudo Random Number Generator Based on L'Ecuyer's SchemeabstractIn this paper, we propose a new lightweight L'Ecuyer-based pseudo random number generator (PRNG). We show that our scheme, despite the very simple functions on which it relies on, is strongly secure in the sense that our number sequences pass the state-of-the-art randomness tests and, importantly, an accurate and deep security analysis shows that it is resistant to a number of attacks. Francesco Buccafurri, Gianluca Lax |
SECRYPT | 1 |
| 2014 | Moving from social networks to social internetworking scenarios: The crawling perspective
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Inf. Sci. | 1 |
| 2013 | Allowing privacy-preserving analysis of social network likesabstractSocial network Likes, as the “Like Button” records of Facebook, can be used to automatically and accurately predict highly sensitive personal attributes. Even though this could be done for non malicious reasons, for example to improve products, services, and targeting, it represents a dangerous invasion of privacy with sometimes intolerable consequences. Anyway, completely defusing the information power of Likes appears improper. In this paper, we propose a mechanism able to keep Likes unlinkable to the identity of their authors, but to allow the user to choose every time she expresses a Like, those non-identifying (even sensitive) attributes she wants to reveal. This way, anonymous analysis relating Likes to various characteristics of the population is preserved, with no risk for users' privacy. The protocol is shown to be secure and also ready to the possible future evolution of social networks towards P2P fully distributed models. Francesco Buccafurri, Lidia Fotia, Gianluca Lax |
PST | 1 |
| 2013 | Bridge analysis in a Social Internetworking Scenario
Francesco Buccafurri, Vincenzo Daniele Foti, Gianluca Lax, Antonino Nocera, Domenico Ursino |
Inf. Sci. | 1 |
| 2012 | Crawling Social Internetworking SystemsabstractIn new generation social networks, we expect that the paradigm of Social Internetworking Systems (SISs, for short) will be more and more important. In this new scenario, the role of Social Network Analysis is of course still crucial but the preliminary step to do is designing a good way to crawl the underlying graph. While this aspect has been deeply investigated in the field of social networks, it is an open issue when moving towards SISs. Indeed, we cannot expect that a crawling strategy which is good for social networks, is still valid in a Social Internetworking Scenario, due to its specific topological features. In this paper, we first confirm the above claim and, then, define a new crawling strategy specifically conceived for SISs. Finally, we show that it fully overcomes the drawbacks of the state-of-the-art crawling strategies. Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
ASONAM | 1 |
| 2012 | Discovering Links among Social Networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino |
ECML/PKDD (2) | 1 |
| 2012 | Privacy-preserving resource evaluation in social networksabstractIn new generation social networks, we expect that the demand of tools allowing the user to effectively control privacy, without relying on the provider trustworthiness, will be more and more increasing. A lot of precious information is currently released by users with no privacy control whenever they evaluate resources, which, for example, is done in Facebook through the “Like Button”. A mechanism allowing the user to express her preferences fully preserving her privacy is thus desired, especially if it is able to protect user privacy also in case of untrustworthy social network provider. In this paper, we propose a solution to this problem, based on a DHT-based P2P social network and on a cryptographic protocol relying on partially blind digital signatures. The protocol is shown to be a solution to the trade-off between feasibility and security, since it guarantees the needed security requirements without including the complex features of existing e-voting systems. Francesco Buccafurri, Lidia Fotia, Gianluca Lax |
PST | 1 |
| 2012 | A probabilistic framework for estimating the accuracy of aggregate range queries evaluated over histograms
Francesco Buccafurri, Filippo Furfaro, Domenico Saccà |
Inf. Sci. | 1 |
| 2011 | A quad-tree based multiresolution approach for two-dimensional summary data
Francesco Buccafurri, Filippo Furfaro, Giuseppe M. Mazzeo, Domenico Saccà |
Inf. Syst. | 1 |
| 2010 | A contextual reading of conditional commitmentsabstractThis paper puts forward a view on conditional commitments as causal rules, using action language K as the specification framework. The proposal builds upon an operational notion of social context, in such a way that conditional commitments are represented as rules in context. This approach enables the manipulation of conditional commitments in terms of the manipulation of the social interactions which provide their social contexts. Moreover, it allows the programmer to exploit the ASP metatheory underlying action language K to analyze, simplify and transform commitment-based protocols. Juan Manuel Serrano, Sergio Saugar, Rosario Laurendi, Francesco Buccafurri |
ECAI | 4 |
| 2010 | Approximating sliding windows by cyclic tree-like histograms for efficient range queries
Francesco Buccafurri, Gianluca Lax |
Data Knowl. Eng. | 1 |
| 2009 | Fortifying the dalì attack on digital signatureabstractIn the recent literature a new vulnerability of digital signature has been addressed, based on a novel mechanism (denoted Dalì attack) allowing ambiguous presentation of electronic documents. This mechanism operates by a non-trivial inclusion into a single polymorphic file of a pair of different contents, encoded through two different format types. In this paper we overcome the main limitation of the above attack, consisting in the necessity of having html among the two involved formats. Here, exploiting an unusual feature of the pdf standard, we are able to enhance the attack in such a way that the two filetypes, namely pdf and tiff, embedded into the polymorphic file are both extremely safe, allowing the attacker to produce a fake document that appears in a format widely accepted in the context of e-government activities both whenever it is signed and whenever it is fraudulently exploited. This significantly increases both the danger and the plausibility of the Dalì attack. Francesco Buccafurri, Gianluca Caminiti, Gianluca Lax |
SIN | 1 |
| 2008 | A Logic Language with Stable Model Semantics for Social Reasoning
Francesco Buccafurri, Gianluca Caminiti, Rosario Laurendi |
ICLP | 1 |
| 2008 | Analysis of QoS in cooperative services for real time applications
Francesco Buccafurri, Pasquale De Meo, Maria Grazia Fugini, Roberto Furnari, Anna Goy, Gianluca Lax, Pasquale Lops, Stefano Modafferi, Barbara Pernici, Domenico Redavid, Giovanni Semeraro, Domenico Ursino |
Data Knowl. Eng. | 1 |
| 2008 | Logic programming with social featuresabstractAbstract In everyday life it happens that a person has to reason out what other people think and how they behave, in order to achieve his goals. In other words, an individual may be required to adapt his behavior by reasoning about the others' mental state. In this paper we focus on a knowledge-representation language derived from logic programming which both supports the representation of mental states of individual communities and provides each with the capability of reasoning about others' mental states and acting accordingly. The proposed semantics is shown to be translatable into stable model semantics of logic programs with aggregates. Francesco Buccafurri, Gianluca Caminiti |
Theory Pract. Log. Program. | 1 |
| 2008 | Enhancing histograms by tree-like bucket indices
Francesco Buccafurri, Gianluca Lax, Domenico Saccà, Luigi Pontieri, Domenico Rosaci |
VLDB J. | 1 |
| 2006 | Logic Programs with Multiple Chances
Francesco Buccafurri, Gianluca Caminiti, Domenico Rosaci |
ECAI | 1 |
| 2006 | Dealing with semantic heterogeneity for improving Web usage
Francesco Buccafurri, Gianluca Lax, Domenico Rosaci, Domenico Ursino |
Data Knowl. Eng. | 1 |
| 2005 | A Social Semantics for Multi-agent Systems
Francesco Buccafurri, Gianluca Caminiti |
LPNMR | 1 |
| 2004 | Reducing Data Stream Sliding Windows by Cyclic Tree-Like Histograms
Francesco Buccafurri, Gianluca Lax |
PKDD | 1 |
| 2004 | Fast range query estimation by N-level tree histograms
Francesco Buccafurri, Gianluca Lax |
Data Knowl. Eng. | 1 |
| 2003 | Pre-computing Approximate Hierarchical Range Queries in a Tree-Like Histogram
Francesco Buccafurri, Gianluca Lax |
DaWaK | 1 |
| 2003 | A Quad-Tree Based Multiresolution Approach for Two-dimensional Summary DataabstractIn many application contexts, like statistical databases, scientific databases, query optimizers, OLAP, and so on, data are often summarized into synopses of aggregate values. Summarization has the great advantage of saving space, but querying aggregate data rather than the original ones introduces estimation errors which cannot be in general avoided, as summarization is a lossy compression. A central problem in designing summarization techniques is to retain a certain degree of accuracy in reconstructing query answers. In this paper we restrict our attention to two-dimensional data, which are relevant for a number of applications, and propose a hierarchical summarization technique, which is combined with the use of indices, i.e. compact structures providing an approximate description of portions of the original data. Experimental results show that the technique gives approximation errors much smaller than other "general purpose" techniques, such as wavelets and various types of multi-dimensional histogram. Francesco Buccafurri, Filippo Furfaro, Domenico Saccà, Cristina Sirangelo |
SSDBM | 1 |
| 2002 | Binary-Tree Histograms with Tree Indices
Francesco Buccafurri, Filippo Furfaro, Gianluca Lax, Domenico Saccà |
DEXA | 1 |
| 2002 | Improving Range Query Estimation on HistogramsabstractHistograms are used to summarize the contents of relations for the estimation of query result sizes into a number of buckets. Several techniques (e.g., MaxDiff and V-Optimal) have been proposed in the past for determining bucket boundaries which provide better estimations. This paper proposes to use 32 bit information (4-level tree index) for each bucket for storing approximated cumulative frequencies at 7 internal intervals of a bucket. Both theoretical analysis and experimental results show that the 4-level tree index provides the best frequency estimation inside a bucket. The index is later added to two well-known techniques for constructing histograms, MaxDiff and V-Optimal, thus obtaining high improvements in the frequency estimation over inter-bucket ranges w.r.t. the original methods. Francesco Buccafurri, Domenico Rosaci, Luigi Pontieri, Domenico Saccà |
ICDE | 1 |
| 2002 | Disjunctive Logic Programs with InheritanceabstractThe paper proposes a new knowledge representation language, called DLP<, which extends disjunctive logic programming (with strong negation) by inheritance. The addition of inheritance enhances the knowledge modeling features of the language providing a natural representation of default reasoning with exceptions. A declarative model-theoretic semantics of DLP< is provided, which is shown to generalize the Answer Set Semantics of disjunctive logic programs. The knowledge modeling features of the language are illustrated by encoding classical nonmonotonic problems in DLP<. The complexity of DLP< is analyzed, proving that inheritance does not cause any computational overhead, as reasoning in DLP< has exactly the same complexity as reasoning in disjunctive logic programming. This is confirmed by the existence of an efficient translation from DLP< to plain disjunctive logic programming. Using this translation, an advanced KR system supporting the DLP< language has been implemented on top of the DLV system and has subsequently been integrated into DLV. Francesco Buccafurri, Wolfgang Faber 0001, Nicola Leone |
Theory Pract. Log. Program. | 1 |
| 2001 | Estimating Range Queries Using Aggregate Data with Integrity Constraints: A Probabilistic Approach
Francesco Buccafurri, Filippo Furfaro, Domenico Saccà |
ICDT | 1 |
| 2001 | On ACTL Formulas Having Linear Counterexamples
Francesco Buccafurri, Thomas Eiter, Georg Gottlob, Nicola Leone |
J. Comput. Syst. Sci. | 1 |
| 2000 | A Logic-Based Approach for Enforcing Access ControlabstractThis paper describes an advanced authorization mechanism based on a logic formalism. The model supports both positive and negative authorizations. It also supports derivation rules by which an authorization can be granted on the basis of the presence Elisa Bertino, Francesco Buccafurri, Elena Ferrari 0001, Pasquale Rullo |
J. Comput. Secur. | 2 |
| 2000 | Enhancing Disjunctive Datalog by ConstraintsabstractThis paper presents an extension of Disjunctive Datalog (DATALOG/sup V,/spl sim//) by integrity constraints. These are of two types: strong, that is, classical integrity constraints and weak, that is, constraints that are satisfied if possible. While strong constraints must be satisfied, weak constraints express desiderata, that is, they may be violated-actually, their semantics tends to minimize the number of violated instances of weak constraints. Weak constraints may be ordered according to their importance to express different priority levels. As a result, the proposed language (call it, DATALOG/sup V,/spl sim/,c/) is well-suited to represent common sense reasoning and knowledge-based problems arising in different areas of computer science such as planning, graph theory optimizations, and abductive reasoning. The formal definition of the language is first given. The declarative semantics of DATALOG/sup V,/spl sim/,c/ is defined in a general way that allows us to put constraints on top of any existing (model-theoretic) semantics for DATALOG/sup V,/spl sim// programs. Knowledge representation issues are then addressed and the complexity of reasoning on DATALOG/sup V,/spl sim/,c/ programs is carefully determined. An in-depth discussion on complexity and expressiveness of DATALOG/sup V,/spl sim/,c/ is finally reported. The discussion contrasts DATALOG/sup V,/spl sim/,c/ to DATALOG/sup V,/spl sim// and highlights the significant increase in knowledge modeling ability carried out by constraints. Francesco Buccafurri, Nicola Leone, Pasquale Rullo |
IEEE Trans. Knowl. Data Eng. | 1 |
| 1999 | A Logical Framework for Reasoning on Data Access Control PoliciesabstractWe propose a logic formalism that naturally supports the encoding of complex security specifications. This formalism relies on a hierarchically structured domain made of subjects, objects and privileges. Authorizations are expressed by logic rules. The formalism supports both negation by failure (possibly unstratified) and true negation. The latter is used to express negative authorizations. It turns out that conflicts may result from a set of authorization rules. Dealing with such conflicts requires the knowledge of the domain structure, such as grantor priorities and object/subject hierarchies, which is used in the deductive process to determine which authorization prevails, if any, on the others. Often, however, conflicts are unsolvable, as they express intrinsic ambiguities. We have devised two semantics as an extension of the well-founded and the stable model semantics of logic programming. We have also defined a number of access policies, each based on two orthogonal choices: one is related to the way of how we cope with multiplicity of authorization sets in case of stable model semantics; the other is concerned with the open/closed assumption. A comparative analysis of the proposed authorization policies, based on their degree of permissivity shows that they form a complete lattice. Elisa Bertino, Elena Ferrari 0001, Francesco Buccafurri, Pasquale Rullo |
CSFW | 3 |
| 1999 | Compressed Datacubes for fast OLAP Applications
Francesco Buccafurri, Domenico Rosaci, Domenico Saccà |
DaWaK | 1 |
| 1999 | Disjunctive Logic Programs with Inheritance
Francesco Buccafurri, Wolfgang Faber 0001, Nicola Leone |
ICLP | 1 |
| 1999 | Enhancing Model Checking in Verification by AI Techniques
Francesco Buccafurri, Thomas Eiter, Georg Gottlob, Nicola Leone |
Artif. Intell. | 1 |
| 1998 | An Authorization Model and Its Formal Semantics
Elisa Bertino, Francesco Buccafurri, Elena Ferrari 0001, Pasquale Rullo |
ESORICS | 2 |
| 1998 | Disjunctive Ordered Logic: Semantics and Expressiveness
Francesco Buccafurri, Nicola Leone, Pasquale Rullo |
KR | 1 |
| 1997 | The Expressive Power of Unique Total Stable Model Semantics
Francesco Buccafurri, Sergio Greco, Domenico Saccà |
ICALP | 1 |
| 1997 | Strong and Weak Constraints in Disjunctive Datalog
Francesco Buccafurri, Nicola Leone, Pasquale Rullo |
LPNMR | 1 |
| 1995 | Disjunctive Ordered Logic
Francesco Buccafurri, Nicola Leone, Luigi Palopoli 0001, Pasquale Rullo |
DEXA | 1 |