VLDB 2026 Research / reviewers in the wild / expert
Daniele Sgandurra
dblp:92/413
· DBLP profile ↗
32ranked-venue papers
1as first author
5since 2021 · last 2024
0000-0001-5238-8068ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 1 first-author · 3 since 2021Systems, architecture and hardware · 4Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | EFACTLS: Effective Active TLS Fingerprinting for Large-Scale Server Deployment CharacterizationabstractActive measurements allow the collection of server characteristics on a large scale that can aid in discovering hidden relations and commonalities among server deployments. Finding these relations opens up new possibilities for clustering and classifying server deployments; for example, identifying a previously unknown cybercriminal infrastructure can be valuable cyber-threat intelligence. In this work, we propose a methodology based on active measurements to acquire Transport Layer Security (TLS) metadata from servers and leverage it for fingerprinting. Our fingerprints capture characteristic behavior of the TLS stack, primarily influenced by the server’s implementation, configuration, and hardware support. Using an empirical optimization strategy that maximizes information gained from every handshake to minimize measurement costs, we generated 10 general-purpose Client Hellos. They served as scanning probes to create an extensive database of TLS configurations to classify servers. We propose the Shannon Entropy to measure collected information and compare different approaches. This study fingerprinted 8 million servers from the Tranco top list and two Command and Control (C2) blocklists over 60 weeks with weekly snapshots. The resulting data formed the foundation for two long-term case studies: classification of Content Delivery Network and C2 servers. Moreover, the detection was fine-grained enough to detect C2 server families. The proposed methodology demonstrated a precision of 99% and enabled a stable identification of new servers over time. This study shows how active measurements can provide valuable security-relevant insights and improve our understanding of the Internet. Markus Sosnowski, Johannes Zirngibl, Patrick Sattler, Georg Carle, Claas Grohnfeldt, Michele Russo, Daniele Sgandurra |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2023 | Protecting Voice-Controllable Devices Against Self-Issued Voice CommandsabstractSelf-issued voice commands leverage the voice-controllable device’s internal speaker to issue malicious voice commands to the device itself. These attacks are a class of voice spoofing attacks particularly challenging to protect from, as it is very hard for a countermeasure solution to infer whether the command comes from an external entity or from the device itself. In this paper, we propose a countermeasure against self-issued voice commands by training a Twin Neural Network to recognise the differences between what is being played and what is being recorded by the voice-controllable device. In fact, these audios are very similar in case of voice command self-issue attacks and different in case of legitimate commands. We start with a security and usability trade-off analysis of countermeasures against voice spoofing attacks, by describing different classes of synthesised voice commands that need to be blocked or allowed, depending on the necessities of the user. Then, we present our solution to protect voice-controllable devices from self-issued commands and show that it correctly classifies commands in the benign (real-user) and malign (self-issued) categories 97% of the times on average. We compare this result with state-of-the-art anomaly detection techniques as a baseline and show that our solution outperforms them. Furthermore, we instantiate our countermeasure on three different classes of devices to measure its performance, and we find that the additional overhead is negligible. Finally, we measure the usability impact of our solution when users interact with the tested device under different conditions, showing that our solution is resistant to environmental changes and regardless of the identity of the user issuing the commands. Sergio Esposito, Daniele Sgandurra, Giampaolo Bella |
EuroS&P | 2 |
| 2022 | ALEXA VERSUS ALEXA: Controlling Smart Speakers by Self-Issuing Voice CommandsabstractWe present ALEXA VERSUS ALEXA (AvA), a novel attack that leverages audio files containing voice commands and audio reproduction methods in an offensive fashion, to gain control of Amazon Echo devices for a prolonged amount of time. AvA leverages the fact that Alexa running on an Echo device correctly interprets voice commands originated from audio files even when they are played by the device itself -- i.e., it leverages a command self-issue vulnerability. Hence, AvA removes the necessity of having a rogue speaker in proximity of the victim's Echo, a constraint that many attacks share. With AvA, an attacker can self-issue any permissible command to Echo, controlling it on behalf of the legitimate user. We have verified that, via AvA, attackers can control smart appliances within the household, buy unwanted items, tamper linked calendars and eavesdrop on the user. We also discovered two additional Echo vulnerabilities, which we call Full Volume and Break Tag Chain. The Full Volume increases the self-issue command recognition rate, by doubling it on average, hence allowing attackers to perform additional self-issue commands. Break Tag Chain increases the time a skill can run without user interaction, from eight seconds to more than one hour, hence enabling attackers to setup realistic social engineering scenarios. By exploiting these vulnerabilities, the adversary can self-issue commands that are correctly executed 99% of the times and can keep control of the device for a prolonged amount of time. We reported these vulnerabilities to Amazon via their vulnerability research program, who rated them with a Medium severity score. In addition, we discuss the results of a set of tests performed on three voluntary Echo-equipped households to verify the feasibility of AvA in real scenarios, finding that the attack remains undetected and operative in most cases. Finally, to assess limitations of AvA on a larger scale, we provide the results of a survey performed on a study group of 18 users, and we show that most of the limitations against AvA are hardly used in practice. Sergio Esposito, Daniele Sgandurra, Giampaolo Bella |
AsiaCCS | 2 |
| 2022 | Evaluating Anti-Virus Effectiveness in LinuxabstractAnti-virus (AV) software is widely recognized as one of the most important defensive tools against malware. Although historically many Linux users considered this operating system to be malware-free, recent research suggests that Linux malware is on the rise. However, to date there has not been a comprehensive observational study on the effectiveness of modern Linux AVs.In this work, we evaluate a range of Linux AVs using a dataset of 43,553 Linux malware samples, conducting our analysis over a period of ten months to identify possible regression effects. We measure the detection rates of Linux AVs available in our local test environment and on an online malware scanning service. Furthermore, we perform a Linux malware capability analysis using the open-source tool CAPA. Overall, the results of this work show that Linux AVs’ signature databases are not well maintained by AV vendors, and that several Linux AVs are affected by regression. In addition, our capability analysis suggests that malware authors are trying to further specialize existing approaches for evading AV software rather than developing new capabilities. Giuseppe Raffa, Daniele Sgandurra, Dan O'Keeffe |
IEEE Big Data | 2 |
| 2021 | RansomClave: Ransomware Key Management using SGXabstractModern ransomware often generate and manage cryptographic keys on the victim’s machine, giving defenders an opportunity to capture exposed keys and recover encrypted data without paying the ransom. However, recent work has raised the possibility of future enclave-enhanced malware that could avoid such mitigations using emerging support for hardware-enforced secure enclaves in commodity CPUs. Nonetheless, the practicality of such enclave-enhanced malware and its potential impact on all phases of the ransomware lifecyle remain unclear. Given the demonstrated capacity of ransomware authors to innovate in order to better extort their victims (e.g. through the adoption of untraceable virtual currencies and anonymity networks), it is important to better understand the risks involved and identify potential mitigations. Alpesh Bhudia, Dan O'Keeffe, Daniele Sgandurra, Darren Hurley-Smith |
ARES | 3 |
| 2020 | Clust-IT: clustering-based intrusion detection in IoT environmentsabstractLow-powered and resource-constrained devices are forming a greater part of our smart networks. For this reason, they have recently been the target of various cyber-attacks. However, these devices often cannot implement traditional intrusion detection systems (IDS), or they can not produce or store the audit trails needed for inspection. Therefore, it is often necessary to adapt existing IDS systems and malware detection approaches to cope with these constraints. Robert P. Markiewicz, Daniele Sgandurra |
ARES | 2 |
| 2020 | 2nd Workshop on Cyber-Security Arms Race (CYSARM 2020)abstractThe goal of CYSARM workshop is to foster collaboration among researchers and practitioners to discuss the various facets and trade-offs of cyber-security. In particular, how new technologies and algorithms might impact the cyber-security of existing or future models and systems. Thanassis Giannetsos, Daniele Sgandurra |
CCS | 2 |
| 2020 | Malware vs Anti-Malware Battle - Gotta Evade 'em All!abstractThe landscape of malware development is ever-changing, creating a constant catch-up contest between the defenders and the adversaries. One of the methodologies that has the potential to pose a significant threat to systems is malware evasion. This is where malware tries to determine whether it is run in a controlled environment, such as a sandbox. Similarly, a malware can also learn how an Anti-Malware System (AMS) decides whether an input program is a malware or in fact benign with the goal of bypassing it. On the other hand, the AMS tries to detect whether a malware sample is performing such evasive checks, e.g. by evaluating the results of Reverse-Turing Test (RTT). This learning process can be viewed as a `battle' between the AMS and the malware, due to the malware attempting to defeat the AMS, where a successful win for the malware would be to evade detection by the AMS and, conversely, a win for the AMS would be to correctly detect the malware and its evasive actions. We propose a visualisation-based system, called Gotta Evade `em All, that allows cyber-security analysts to clearly see the evasive and anti-evasive actions performed by the malware and the AMS during the battle. Emily J. Chaffey, Daniele Sgandurra |
VizSec | 2 |
| 2020 | Improved Proofs Of Retrievability And Replication For Data Availability In Cloud StorageabstractAbstract For a high level of data availability and reliability, a common strategy for cloud service providers is to rely on replication, i.e. storing several replicas onto different servers. To provide cloud users with a strong guarantee that all replicas required by them are actually stored, many multi-replica integrity auditing schemes were proposed. However, most existing solutions are not resource economical since users need to create and upload replicas of their files by themselves. A multi-replica solution called Mirror is presented to overcome the problems, but we find that it is vulnerable to storage saving attack, by which a dishonest provider can considerably save storage costs compared to the costs of storing all the replicas honestly—while still can pass any challenge successfully. In addition, we also find that Mirror is easily subject to substitution attack and forgery attack, which pose new security risks for cloud users. To address the problems, we propose some simple yet effective countermeasures and an improved proofs of retrievability and replication scheme, which can resist the aforesaid attacks and maintain the advantages of Mirror, such as economical bandwidth and efficient verification. Experimental results show that our scheme exhibits comparable performance with Mirror while achieving high security. Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Zhengping Jin, Qiaoyan Wen, Daniele Sgandurra |
Comput. J. | 7 |
| 2019 | A game of "Cut and Mouse": bypassing antivirus by simulating user inputsabstractTo protect their digital assets from malware attacks, most users and companies rely on anti-virus (AV) software. But AVs' protection is a full-time task and AVs are engaged in a cat-and-mouse game where malware, e.g., through obfuscation and polymorphism, denial of service attacks and malformed packets and parameters, try to circumvent AV defences or make them crash. On the other hand, AVs react by complementing signature-based with anomaly or behavioral detection, and by using OS protection, standard code, and binary protection techniques. Further, malware counter-act, for instance by using adversarial inputs to avoid detection, et cetera. This paper investigates two novel moves for the malware side. The first one consists in simulating mouse events to control AVs, namely to send them mouse "clicks" to deactivate their protection. We prove that many AVs can be disabled in this way, and we call this class of attacks Ghost Control. The second one consists in controlling high-integrity white-listed applications, such as Notepad, by sending them keyboard events (such as "copy-and-paste") to perform malicious operations on behalf of the malware. We prove that the anti-ransomware protection feature of some AVs can be bypassed if we use Notepad as a "puppet" to rewrite the content of protected files as a ransomware would do. Playing with the words, and recalling the cat-and-mouse game, we call this class of attacks Cut-and-Mouse. Ziya Alper Genç, Gabriele Lenzini, Daniele Sgandurra |
ACSAC | 3 |
| 2019 | 1st Workshop on Cyber-Security Arms Race (CYSARM 2019)abstractThe goal of CYSARM workshop is to foster collaboration among researchers and practitioners to discuss the various facets and trade-offs of cyber-security. In particular, how new technologies and algorithms might impact the cyber-security of existing or future models and systems. Thanassis Giannetsos, Daniele Sgandurra |
CCS | 2 |
| 2019 | On Deception-Based Protection Against Cryptographic Ransomware
Ziya Alper Genç, Gabriele Lenzini, Daniele Sgandurra |
DIMVA | 3 |
| 2019 | Exact Inference Techniques for the Analysis of Bayesian Attack GraphsabstractAttack graphs are a powerful tool for security risk assessment by analysing network vulnerabilities and the paths attackers can use to compromise network resources. The uncertainty about the attacker's behaviour makes Bayesian networks suitable to model attack graphs to perform static and dynamic analysis. Previous approaches have focused on the formalization of attack graphs into a Bayesian model rather than proposing mechanisms for their analysis. In this paper we propose to use efficient algorithms to make exact inference in Bayesian attack graphs, enabling the static and dynamic network risk assessments. To support the validity of our approach we have performed an extensive experimental evaluation on synthetic Bayesian attack graphs with different topologies, showing the computational advantages in terms of time and memory use of the proposed techniques when compared to existing approaches. Luis Muñoz-González, Daniele Sgandurra, Martín Barrère, Emil C. Lupu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Lightweight Classification of IoT Malware Based on Image RecognitionabstractThe Internet of Things (IoT) is an extension of the traditional Internet, which allows a very large number of smart devices, such as home appliances, network cameras, sensors and controllers to connect to one another to share information and improve user experiences. IoT devices are micro-computers for domain-specific computations rather than traditional function-specific embedded devices. This opens the possibility of seeing many kinds of existing attacks, traditionally targeted at the Internet, also directed at IoT devices. As shown by recent events, such as the Mirai and Brickerbot botnets, DDoS attacks have become very common in IoT environments as these lack basic security monitoring and protection mechanisms. In this paper, we propose a novel light-weight approach for detecting DDos malware in IoT environments. We extract the malware images (i.e., a one-channel gray-scale image converted from a malware binary) and utilize a light-weight convolutional neural network for classifying their families. The experimental results show that the proposed system can achieve 94:0% accuracy for the classification of goodware and DDoS malware and 81:8% accuracy for the classification of goodware and two main malware families. Jiawei Su, Danilo Vasconcellos Vargas, Sanjiva Prasad, Daniele Sgandurra, Yaokai Feng, Kouichi Sakurai |
COMPSAC (2) | 4 |
| 2018 | Risk analysis of Android applications: A user-centric solution
Gianluca Dini, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi, Andrea Saracino, Daniele Sgandurra |
Future Gener. Comput. Syst. | 6 |
| 2018 | MADAM: Effective and Efficient Behavior-based Android Malware Detection and PreventionabstractAndroid users are constantly threatened by an increasing number of malicious applications (apps), generically called malware. Malware constitutes a serious threat to user privacy, money, device and file integrity. In this paper we note that, by studying their actions, we can classify malware into a small number of behavioral classes, each of which performs a limited set of misbehaviors that characterize them. These misbehaviors can be defined by monitoring features belonging to different Android levels. In this paper we present MADAM, a novel host-based malware detection system for Android devices which simultaneously analyzes and correlates features at four levels: kernel, application, user and package, to detect and stop malicious behaviors. MADAM has been specifically designed to take into account those behaviors that are characteristics of almost every real malware which can be found in the wild. MADAM detects and effectively blocks more than 96 percent of malicious apps, which come from three large datasets with about 2,800 apps, by exploiting the cooperation of two parallel classifiers and a behavioral signature-based detector. Extensive experiments, which also includes the analysis of a testbed of 9,804 genuine apps, have been conducted to show the low false alarm rate, the negligible performance overhead and limited battery consumption. Andrea Saracino, Daniele Sgandurra, Gianluca Dini, Fabio Martinelli |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2017 | Efficient Attack Graph Analysis through Approximate InferenceabstractAttack graphs provide compact representations of the attack paths an attacker can follow to compromise network resources from the analysis of network vulnerabilities and topology. These representations are a powerful tool for security risk assessment. Bayesian inference on attack graphs enables the estimation of the risk of compromise to the system’s components given their vulnerabilities and interconnections and accounts for multi-step attacks spreading through the system. While static analysis considers the risk posture at rest, dynamic analysis also accounts for evidence of compromise, for example, from Security Information and Event Management software or forensic investigation. However, in this context, exact Bayesian inference techniques do not scale well. In this article, we show how Loopy Belief Propagation—an approximate inference technique—can be applied to attack graphs and that it scales linearly in the number of nodes for both static and dynamic analysis, making such analyses viable for larger networks. We experiment with different topologies and network clustering on synthetic Bayesian attack graphs with thousands of nodes to show that the algorithm’s accuracy is acceptable and that it converges to a stable solution. We compare sequential and parallel versions of Loopy Belief Propagation with exact inference techniques for both static and dynamic analysis, showing the advantages and gains of approximate inference techniques when scaling to larger attack graphs. Luis Muñoz-González, Daniele Sgandurra, Andrea Paudice, Emil C. Lupu |
ACM Trans. Priv. Secur. | 2 |
| 2016 | Formalizing Threat Models for Virtualized Systems
Daniele Sgandurra, Erisa Karafili, Emil C. Lupu |
DBSec | 1 |
| 2015 | Design and Development of a Facebook Application to Raise Privacy AwarenessabstractEveryday people upload a large number of private pictures on online social networks (OSNs). Users trust OSNs to keep their pictures private, e.g. by making them available to their social friends only. Unfortunately, OSN security controls are not always strong enough and malicious people may exploit these weaknesses to potentially see any user's private pictures. It might even possible to access private photos posted on an OSN without circumventing its security policies. In fact, users sometimes add to their social circles acquaintances, recently met people, which might not be completely trusted. Furthermore, they occasionally allow third-party applications to access their pictures. These conditions imply that, to keep their photos private, users must trust all the security controls implemented by OSNs and all of their social friends (and how they interact with third-party applications). Actually, there are some situations in which these assumptions are not met and some data that users believed to be private might also be accessed by unknown people. The goal of this paper is to raise awareness on the problem of privacy of online pictures and to have OSN users think more carefully about how they use third-party applications and how they choose their friends online. To this end, we discuss a use-case of a Facebook application, which we have developed, that exploits some weaknesses and users' assumptions to gather a huge amount of private pictures. Gianpiero Costantino, Daniele Sgandurra |
PDP | 2 |
| 2015 | Detection of repackaged mobile applications through a collaborative approachabstractSummary Repackaged applications are based on genuine applications, but they subtlety include some modifications. In particular, trojanized applications are one of the most dangerous threats for smartphones. Malware code may be hidden inside applications to access private data or to leak user credit. In this paper, we propose a contract‐based approach to detect such repackaged applications, where a contract specifies the set of legal actions that can be performed by an application. Current methods to generate contracts lack information from real usage scenarios, thus being inaccurate and too coarse‐grained. This may result either in generating too many false positives or in missing misbehaviors when verifying the compliance between the application and the contract. In the proposed framework, application contracts are generated dynamically by a central server merging execution traces collected and shared continuously by collaborative users executing the application. More precisely, quantitative information extracted from execution traces is used to define a contract describing the expected application behavior, which is deployed to the cooperating users. Then, every user can use the received contract to check whether the related application is either genuine or repackaged. Such a verification is based on an enforcement mechanism that monitors the application execution at run‐time and compares it against the contract through statistical tests. Copyright © 2014 John Wiley & Sons, Ltd. Alessandro Aldini, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
Concurr. Comput. Pract. Exp. | 4 |
| 2015 | AntiCheetah: Trustworthy computing in an outsourced (cheating) environment
Roberto Di Pietro, Flavio Lombardi, Fabio Martinelli, Daniele Sgandurra |
Future Gener. Comput. Syst. | 4 |
| 2014 | A Scenario Method to Automatically Assess ICT RiskabstractWe present an assessment of ICT systems that merges a scenario approach and a Monte Carlo method. To automate the assessment, we have developed two tools. The first one builds a formal description of the vulnerabilities in the target system and of the attacks they enable. Starting from this description, the second tool consider each scenario of interest and it simulate several times how intelligent and adaptive threat agents compose these attacks to reach some goals. By collecting samples in these simulations, this tool returns a database to compute statistics of interest for the assessment, such as the success probability of the agents or their average impacts. After outlining the design of the tools, we discuss a test case to show how they are exploited in a real assessment to manage the corresponding risk. Fabrizio Baiardi, Fabio Corò, Federico Tonelli, Daniele Sgandurra |
PDP | 4 |
| 2014 | Automating the assessment of ICT risk
Fabrizio Baiardi, Fabio Corò, Federico Tonelli, Daniele Sgandurra |
J. Inf. Secur. Appl. | 4 |
| 2013 | Probabilistic Contract Compliance for Mobile ApplicationsabstractWe propose PICARD (ProbabIlistic Contract on Android), a framework to generate probabilistic contracts to detect repackaged applications for Android smart phones. A contract describes the sequences of actions that an application is allowed to perform at run-time, i.e. its legal behavior. In PICARD, contracts are generated from the set of traces that represent the usage profile of the application. Both the contract and the application's run-time behavior are represented through clustered probabilistic automata. At run-time, the PICARD monitoring system verifies the compliance of the application trace with the contract. This approach is useful in detecting repackaged applications, whose behavior is strongly similar to the original application but it differs only from small paths in the traces. In this paper, we discuss the framework of PICARD for describing and generating contracts through probabilistic automata and introduce the notion of Action Node, a cluster of related system calls, used to represent high level operations. Then, we present a first set of preliminary experiments on repackaged applications, to evaluate the viability of the proposed approach. Gianluca Dini, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
ARES | 4 |
| 2013 | How to grant less permissions to facebook applicationsabstractSingle Sign-On (SSO) is an authentication procedure that allows users to adopt the same credentials to access multiple services. On the other hand, OAuth 2.0 is a protocol that enables authorized applications to access data that are stored in a resource server. A practical example of the adoption of SSO with OAuth 2.0 is given by all the websites or applications that use the “Log in with Facebook” procedure to authenticate users already registered with Facebook. In this paper, we propose a mechanism that exploits a weakness of OAuth 2.0 and a missing control of the website to show how it is possible to register a user by reducing the number of scopes that the website requires with the “Log in with Facebook” procedure. Finally, we illustrate two examples that exploit the proposed mechanism and provide a solution to address the problem. Gianpiero Costantino, Fabio Martinelli, Daniele Sgandurra |
IAS | 3 |
| 2013 | Towards enforcing on-the-fly policies in BYOD environmentsabstractThe Bring Your Own Device (BYOD) paradigm is becoming extremely popular across all kind of organizations. In fact, employees are continually trying to incorporate their personal devices, e.g. smartphones and tablets, into the office to perform some of their work or simply to access the Internet with a device they trust or they are more familiar with. Unfortunately, several security issues may arise from all these external devices accessing the corporate network. To address these issues, in this paper we propose a framework that enforces on-the-fly instantiated policies inside organizations using trusted BYOD technologies. The proposed framework implements a role-based access control system based upon user identity and her current context. To this end, each user receives a specific policy from a server based upon the current role and context. The effective user identity is confirmed using OAuth 2.0, while the device integrity and policy enforcement is ensured by means of a on-device root-of-trust and an enforcer running on each device. Gianpiero Costantino, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
IAS | 4 |
| 2011 | An Obfuscation-Based Approach against Injection AttacksabstractWe present an obfuscation strategy to protect a program against injection attacks. The strategy represents the program as a set of code fragments in-between two consecutive system calls (the system blocks) and a graph that represents the execution order of the fragment (the system block graph). The system blocks and the system block graph are partitioned between two virtual machines (VMs). The Blocks-VM stores and executes the system blocks but does not store any information on how control flows across the system blocks. This information is represented only by the system block graph stored in the Graph-VM, which correctly sequentializes the system blocks by analyzing the system block graph and accessing the Blocks-VM. At run-time, each time a system block ends, i.e. the program issues a system call, the execution of the Blocks-VM is frozen and control is transferred to the Graph-VM. After deducing the next system block to be executed from the system block graph, the current system block and the current system call, the Graph-VM updates the return address in the Blocks-VM so that the correct system block is executed and then resumes the Blocks-VM. To protect code integrity, the Graph-VM also stores a hash of each block. The overall strategy results in a clean separation between the program and its control-flow and this is important whenever the Graph-VM is in full control of the user whereas the Blocks-VM may be attacked through code injection. The Graph-VM can discover these attacks because either the current system call is not present in the original program or the hash of the current block is invalid. In all these cases, the Graph-VM halts the execution of the program. We present the algorithm that maps the program source code into the system blocks and the system block graph and discuss a first implementation of the run-time architecture along with some performance results. Fabrizio Baiardi, Daniele Sgandurra |
ARES | 2 |
| 2011 | Attestation of integrity of overlay networks
Fabrizio Baiardi, Daniele Sgandurra |
J. Syst. Archit. | 2 |
| 2009 | PsycoTrace: Virtual and Transparent Monitoring of a Process SelfabstractPsycoTrace is a set of tools to protect a process P from attacks that alter P self as specified by its source code. P self is specified in terms of legal traces of system calls and of assertions on P status paired with each call. In turn, legal traces are specified through a context-free grammar returned by a static analysis of P program that may also compute assertions. At run-time, each time P invokes a system call, PsycoTrace checks that the trace is coherent with the grammar and assertions are satisfied. To increase overall robustness, PsycoTrace's run-time tool relies on two virtual machines that run, respectively, P and the monitoring system. This strongly separates the monitored machine that runs P from the monitoring one. The current implementation is fully transparent to P but not to the OS because a kernel module in the monitored machine intercepts system calls. We describe PsycoTrace overall architecture and focus on the run-time and introspection tools that enable the monitoring machine to check that a trace is legal and to transparently access the memory of the other machine to evaluate assertions. Lastly, a preliminary evaluation of the run-time overhead is discussed. Fabrizio Baiardi, Dario Maggiari, Daniele Sgandurra, Francesco Tamberi |
PDP | 3 |
| 2008 | Semantics-Driven Introspection in a Virtual EnvironmentabstractSemantics-driven monitoring discovers attacks against a process by evaluating invariants on the process state. We propose an approach that increases the robustness and the transparency of the run-time monitoring system by introducing two virtual machines (VMs) running on the same platform. One VM runs the monitored process, i.e. the process P to be protected, while the other one evaluates invariants on P state each time P invokes a system call. To this purpose, an Introspection Library allows the monitoring VM to access the memory and the processor registers of the monitored VM. After describing the overall architecture, we focus on the Introspection Library and the problems posed by the introspection of variables in the memory of a program running in a distinct VM to evaluate invariants. A first prototype implementation is also presented together with preliminary performance results. Francesco Tamberi, Dario Maggiari, Daniele Sgandurra, Fabrizio Baiardi |
IAS | 3 |
| 2007 | Building Trustworthy Intrusion Detection through VM IntrospectionabstractPsyco-Virt is a high assurance intrusion detection tool that merges host and network intrusion detection technologies with virtual machine introspection. Psyco-Virt architecture includes a cluster of virtual machines, the monitored VMs, which run the OS and applications of interest, and a further VM, the introspection one. Several agents distributed across the monitored VMs execute network and host IDS tools to discover attempted intrusions/attacks on the monitored VMs. The introspection VM makes the detection tools trustworthy by running an introspector and a director to discover any attempt to maliciously modify the kernel, the agents and the IDSes hosted on a monitored VM. On each monitored VM a collector gathers the alerts generated by the agents and forwards them to the director through a control network dedicated to data exchange among the agents and the introspection VM. The director on the introspection VM filters all the alerts and delegates the execution of a proper action to a notifier whenever an intrusion or an attempt to modify the IDSes is detected. In such cases, a monitored VM can either be stopped or frozen and its current state saved in a file for a later, deeper inspection. After describing Psyco-Virt, we discuss some examples of agents and functions using introspection and present preliminary results and performance figures of a first prototype. Fabrizio Baiardi, Daniele Sgandurra |
IAS | 2 |
| 2007 | Managing Critical Infrastructures through Virtual Network Communities
Fabrizio Baiardi, Gaspare Sala, Daniele Sgandurra |
CRITIS | 3 |