VLDB 2026 Research / reviewers in the wild / expert
Ilaria Matteucci
dblp:99/3823
· DBLP profile ↗
39ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0002-5936-8470ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 since 2021Software engineering, systems software and programming languages · 7 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 since 2021Artificial intelligence and machine learning · 5Systems, architecture and hardware · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 3Computer networks · 2 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ontology-Driven Detection of Traffic Light Manipulation in Intelligent Transportation Systems
Elena Cardillo, Marco De Vincenzi 0001, Maria Taverniti, Ilaria Matteucci |
ICISSP (2) | 4 |
| 2025 | OLIVE: Adaptive Containerized Architecture for Multi-Factor Authentication in V2XabstractOLIVE is a containerized Multi-Factor Authentication (MFA) architecture designed to adapt to diverse security requirements in Vehicle-to-Everything (V2X) communications. By integrating multiple authentication factors, it provides adaptability and scalability to match the required level of security. Beyond the standard three authentication factors, OLIVE supports additional custom factors housed in independent containers. The nature of this modular design and its alignment with current security standards enable efficient resource management while ensuring compatibility with both autonomous and nonautonomous vehicles. OLIVE's adaptability positions it as a versatile solution for various applications, including dynamic Electric Vehicle (EV) charging and zero-trust architectures. Marco De Vincenzi 0001, Chiara Bodei, Ilaria Matteucci |
VTC2025-Spring | 3 |
| 2025 | TLM: A Spatial Messaging Language for Autonomous Vehicle NavigationabstractAutonomous Vehicles (AVs) rely on sensor-based perception systems and high-definition maps for navigation. How-ever, their performance may degrade in challenging conditions such as poor visibility, unpredictable traffic conditions, or GNSS-denied environments like urban canyons or temporary construction zones. To address these limitations, we introduce Time-Logic-Map (TLM), a spatial messaging language that enables the road infrastructure to broadcast structured, machine-readable messages to supplement AV perception and support decision-making. This approach reduces the dependence on onboard sensors and describes road logic through machine-oriented language. TLM organizes road information into three layers: map, defining road geometry and a local 3D Cartesian coordinate system; logic, encoding the structural layout of roads and the precedence rules governing vehicle movements; and time, broadcasting real-time information like traffic signal phases. We describe modular design using multiple practical examples in standard and complex intersections, as well as in road construction zones. Marco De Vincenzi 0001, Chiara Bodei, Ilaria Matteucci, Sanjay E. Sarma, Stephen S. Ho |
VTC2025-Fall | 3 |
| 2024 | Formal analysis of an AUTOSAR-based basic software moduleabstractAbstract The widespread use of advanced driver assistance systems in modern vehicles, together with their integration with the Internet and other road nodes, has made vehicle more vulnerable to cyber-attacks. To address these risks, the automotive industry is increasingly focusing on the development of security solutions: formal methods and software verification techniques, which have been successfully applied to a number of safety-critical systems, could be a promising approach in the automotive area. In this work, we concentrate on in-vehicle communications, provided by many Electronic Control Units (ECUs) that work together thanks to serial protocols such as Controller Area Network (CAN). However, increasing connectivity exposes the internal network to a variety of cyber-risks. Our aim is to formally verify the AUTOSAR-based Basic Software module called CINNAMON, designed to ensure confidentiality, integrity, and authentication at the same time for traffic exchanged over CAN protocol. More precisely, it adds confidentiality guarantees to the Secure Onboard Communication (SecOC) module. We formally analyze CINNAMON with the verification tool Tamarin. Our analysis shows that CINNAMON could be an effective security solution, as it can ensure the desired properties, in particular, confidentiality in a send-receive scenario between two ECUs. Finally, we describe a potential application scenario. Chiara Bodei, Marco De Vincenzi 0001, Ilaria Matteucci |
Int. J. Softw. Tools Technol. Transf. | 3 |
| 2023 | Application of Secure Two-Party Computation in a Privacy-Preserving Android AppabstractData privacy has become increasingly important in recent years, with the rise of cyber threats and the unauthorized sharing of sensitive information. Our work within the E-Corridor project has focused on developing a secure framework for sharing information in multimodal transport systems, while ensuring data privacy is maintained. Our implementation of a two-party computation schema using Yao’s garbled circuits in an Android mobile setting has enabled us to create an application that allows users to find points of interest, e.g., restaurants or hotels, near specific areas without sharing any personal information. The application matches user requests using the secure two-party without disclosing any of the user’s preferences with external actors. We design a threat model based on LINDDUN to show the reliability of our project. It highlights also the potential of using secure computing techniques to enable information sharing while maintaining privacy. Our work demonstrates the importance of prioritizing data privacy in our increasingly interconnected world and the potential of secure two-party computing techniques in achieving this goal. Besides, this framework is flexible and can be extended to various domains where data privacy is of utmost importance. Marco De Vincenzi 0001, Ilaria Matteucci, Fabio Martinelli, Stefano Sebastio |
ARES | 2 |
| 2023 | Securing Automotive Ethernet: Design and Implementation of Security Data Link SolutionsabstractIn recent years, the automotive industry has undergone a revolution in which data has become one of the most important element of vehicle functionality. However, most of the in-vehicle networking paradigms have limitations in accommodating this data surge. To address this need, Automotive Ethernet (AE) has emerged as a promising solution. Concurrently, there is an urgent demand to guarantee data security and privacy within vehicle networks by designing ad hoc vehicular solutions. For this reason, our study undertakes the design and evaluation of four distinct ISO/OSI layer 2 security configurations, here named profiles, tailored to AE. By leveraging advanced security techniques such as MACsec and SecOC-related solutions, these profiles are engineered to ensure robust data confidentiality, integrity, and authenticity. To assess their efficacy, we created a testbed with Raspberry units to emulate an in-vehicle environment. We carried out a comprehensive timing analyses to uncover the performance attributes of each solution. We aim to provide insights for the development of secure and efficient data communication systems within the in-vehicle networks. Marco De Vincenzi 0001, Chiara Bodei, Ilaria Matteucci |
AICCSA | 3 |
| 2023 | Vehicle Data Collection: A Privacy Policy Analysis and ComparisonabstractIn recent years, data can be considered the new fuel for road vehicle functionalities like driver-assistance systems or customized services. Therefore, the carmakers with their phone apps, synced with the infotainment system, can collect information from the drivers and vehicles to be processed inside or outside the car. In this context, we analyze different carmakers’ privacy policies to define their readability and compliance with the EU General Data Protection Regulation, and provide analysis of carmakers’ data collection. Besides, for the first time, we compare the most significant privacy regulations in automotive. Finally, we create an interactive dashboard to compare the different carmakers’ policies and provide users with an efficient instrument to understand some relevant privacy aspects like which data the carmakers declare to collect. We find that carmakers could collect a large number of users and vehicle data, but, in some cases, the privacy policies seem to be quite challenging to read and do not provide some information like how collected data are protected or stored. Chiara Bodei, Gianpiero Costantino, Marco De Vincenzi 0001, Ilaria Matteucci, Anna Monreale |
ICISSP | 4 |
| 2023 | From Hardware-Functional to Software-Defined Vehicles and their Security IssuesabstractOver the next few years, the automotive industry is set to experience a revolutionary transformation driven by several interconnected trends such as autonomous driving, connected vehicles, and electrification. Our research focuses on Software-Defined Vehicles (SDVs), their definition, and an analysis of their possible cybersecurity issue. SDV is a new concept that is changing the definition of vehicles from purely hardware-based to software-oriented. The research analyzes the SDV security following the ISO/SAE 21434 guidelines, performing a complete vulnerability assessment to determine the main possible threats and their impact on different aspects like safety and operations. The findings suggest that SDVs may be the future of the automotive industry and will offer greater convenience and sustainability, throughout the vehicle life cycle but only if appropriate solutions to mitigate potential security threats like denial-of-service or jamming attacks, will be implemented. Chiara Bodei, Marco De Vincenzi 0001, Ilaria Matteucci |
INDIN | 3 |
| 2023 | Electric Vehicle Security and Privacy: A Comparative Analysis of Charging MethodsabstractIn the next decade, electric road vehicles have the potential to reduce climate change and improve mobility. However, not all charging methods are equally secure and private, so this work provides a comprehensive analysis of the security and privacy of various EV charging methods and highlights the importance of addressing vulnerabilities to meet homologation standards. Five charging methods are described in terms of physical components, communication protocols, and standards. This research identifies weaknesses in each method and determines which are less prone to cyber attacks or privacy disclosures. The impact of different charging methods on vehicle homologation is also discussed, as required by the cybersecurity regulation UNECE R155. A mapping is provided between vulnerabilities and suggested mitigations from the regulation. The evidence suggests that different charging methods result in different security and privacy levels, with conductive methods being more vulnerable to security attacks and privacy disclosure, while methods with fewer components may reduce security and privacy risks. Gianpiero Costantino, Marco De Vincenzi 0001, Fabio Martinelli, Ilaria Matteucci |
VTC2023-Spring | 4 |
| 2023 | A Privacy-Preserving Solution for Intelligent Transportation Systems: Private Driver DNAabstractThe rising connection of vehicles with the road infrastructure enables the creation of data-driven applications to offer drivers customized services. At the same time, these opportunities require innovative solutions to protect the drivers’ privacy in a complex environment like an Intelligent Transportation System (ITS). This need is even more relevant when data are used to retrieve personal behaviors or attitudes. In our work, we propose a privacy-preserving solution, called Private Driver DNA, which designs a possible architecture, allowing drivers of an ITS to receive customized services. The proposed solution is based on the concept of Driver DNA as characterization of driver’s driving style. To assure privacy, we perform the operations directly on sanitized data, using the Order Revealing Encryption (ORE) method. Besides, the proposed solution is integrated with ITS architecture defined in the European project E-Corridor. The result is an effective privacy-preserving architecture for ITS to offer customized products, which can be used to address drivers’ behaviors, for example, to environmental-friendly attitudes or a more safe driving style. We test Private Driver DNA using a synthetic dataset generated with the vehicle simulator CARLA. We compare ORE with another encryption method like Homomorphic Encryption (HE) and some other privacy-preserving schemas. Besides, we quantify privacy gain and data loss utility after the data sanitization process. Gianpiero Costantino, Marco De Vincenzi 0001, Fabio Martinelli, Ilaria Matteucci |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | SECPAT: Security Patterns for Resilient Automotive E / E ArchitecturesabstractAutomated driving requires increasing networking of vehicles, which in turn broadens their attack surface. In this paper, we describe several security design patterns that target critical steps in automotive attack chains and mitigate their con-sequences. These patterns enable the detection of anomalies in the firmware when booting, detect anomalies in the communication in the vehicle, prevent unauthorized control units from successfully transmitting messages, offer a way of transmitting security-related events within a vehicle network and reporting them to units external to the vehicle, and ensure that communication in the vehicle is secure. Using the example of a future high-level Electrical / Electronic (E / E) architecture, we also describe how these security design patterns can be used to become aware of the current attack situation and how to react to it. Christian Plappert, Florian Fenzl, Roland Rieke, Ilaria Matteucci, Gianpiero Costantino, Marco De Vincenzi 0001 |
PDP | 4 |
| 2022 | CAHOOT: a Context-Aware veHicular intrusiOn detectiOn sysTemabstractSoftware in modern vehicles is becoming increasingly complex and subject to vulnerabilities that an intruder can exploit to alter the functionality of vehicles. To this purpose, we introduce CAHOOT, a novel context-aware Intrusion Detection System (IDS) capable of detecting potential intrusions in both human and autonomous driving modes. In CAHOOT, context information consists of data collected at run-time by vehicle’s sensors and engine. Such information is used to determine drivers’ habits and information related to the environment, like traffic conditions. In this paper, we create and use a dataset by using a customised version of the MetaDrive simulator capable of collecting both human and AI driving data. Then we simulate several types of intrusions while driving: denial of service, spoofing and replay attacks. As a final step, we use the generated dataset to evaluate the CAHOOT algorithm by using several machine learning methods. The results show that CAHOOT is extremely reliable in detecting intrusions. Davide Micale, Gianpiero Costantino, Ilaria Matteucci, Florian Fenzl, Roland Rieke, Giuseppe Patanè 0002 |
TrustCom | 3 |
| 2022 | Full-protocol safety analysis of CINNAMONabstractThe gap between safety and security solutions in the automotive domain is still far from being filled. Till now, the automotive industries have been mainly devoted to provide safety relevant solution. The increasing adoption of electronic solutions to regulate vehicles’ functionalities moves the attention also to cyber-security issues. In this paper, we present a full-protocol analysis of the CINNAMON intra-vehicle communication protocol, showing how it is able to satisfy both security and safety AUTOSAR requirements. In particular, we include in the analysis the synchronization messages, which were previously excluded. Luca Dariz, Gianpiero Costantino, Ilaria Matteucci |
VTC Spring | 3 |
| 2022 | Designing and implementing an AUTOSAR-based Basic Software Module for enhanced securityabstractElectronic Control Units (ECUs) communicate with each other to accomplish the functionalities of modern vehicles. ECUs form an in-vehicle network that is precisely regulated and must be adequately protected from malicious activity, which has had several outbreaks in recent years. Therefore, we present CINNAMON, an AUTOSAR-based Basic Software Module that aims at confidentiality, integrity and authentication, all at the same time, for the traffic exchanged over the bus protocols that AUTOSAR supports. CINNAMON in fact stands for Confidential, INtegral aNd Authentic onboard coMmunicatiON. This article introduces the requirements and specification of CINNAMON in a differential fashion with respect to the existing Secure Onboard Communication Basic Software Module, which does not include confidentiality. As a result, CINNAMON exceeds SecOC at least against information gathering attacks. The article then defines three security profiles, regulating also the freshness attribute appropriately. Most importantly, CINNAMON is not a simple academic exercise because it is implemented in a laboratory environment on commercial ECUs, thus reaching the level of TRL 4, “Component and/or breadboard validation in laboratory environment”. The runtimes obtained on inexpensive devices are reassuring, paving the way for a possible large-scale application. Giampaolo Bella, Pietro Biondi, Gianpiero Costantino, Ilaria Matteucci |
Comput. Networks | 4 |
| 2022 | A Delphi study to recognize and assess systems of systems vulnerabilitiesabstractSystem of Systems (SoS) is an emerging paradigm by which independent systems collaborate by sharing resources and processes to achieve objectives that they could not achieve on their own. In this context, a number of emergent behaviors may arise that can undermine the security of the constituent systems. We apply the Delphi method with the aims to improve our understanding of SoS security and related problems, and to investigate their possible causes and remedies. Experts on SoS expressed their opinions and reached consensus in a series of rounds by following a structured questionnaire. The results show that the experts found more consensus in disagreement than in agreement about some SoS characteristics, and on how SoS vulnerabilities could be identified and prevented. From this study we learn that more work is needed to reach a shared understanding of SoS vulnerabilities, and we leverage expert feedback to outline some future research directions. Miguel Angel Olivero, Antonia Bertolino, Francisco José Domínguez Mayo, Ilaria Matteucci, María José Escalona Cuaresma |
Inf. Softw. Technol. | 4 |
| 2020 | Analysis of Functional Safety in a secure implementation of CAN ProtocolabstractIn modern vehicles, functionalities are typically managed by Electronic Control Units (ECUs). They communicate each other by using the CAN bus protocol, standardized as ISO 11898-1:2015. However, the CAN protocol was not meant to be secure: messages are sent in clear. In the last decade, several attempts to secure the CAN protocol have been implemented. Here, we focus on TOUCAN [1], [2] and we propose and study a revised version of TOUCAN protocol enhanced from a functional safety prospective and compliant with AUTOSAR safety and security guidelines. In particular, we analyse and simulate the communication robustness of the new version of TOUCAN against transmission errors. Gianpiero Costantino, Luca Dariz, Ilaria Matteucci |
INDIN | 3 |
| 2020 | Digital persona portrayal: Identifying pluridentity vulnerabilities in digital life
Miguel Angel Olivero, Antonia Bertolino, Francisco José Domínguez Mayo, María José Escalona Cuaresma, Ilaria Matteucci |
J. Inf. Secur. Appl. | 5 |
| 2019 | Implementing CAN bus security by TOUCANabstractModern vehicles embed a lot of software that turns them into Cyper-Physical Systems (CPS). Electronic Control Units (ECUs) communicate through the CAN bus protocol, which was not designed to be secure. This paper presents a proof-of-concept of TOUCAN, a new security protocol designed to secure CAN bus communications following the AUTOSAR standard. The presentation introduces design, implementation and performance of TOUCAN on a test-bed composed by two inexpensive boards that can be demonstrated to exchange secure TOUCAN frames. Pietro Biondi, Giampaolo Bella, Gianpiero Costantino, Ilaria Matteucci |
MobiHoc | 4 |
| 2019 | Are you secure in your car?: posterabstractModern vehicles abound with Electronic Control Units (ECUs) that need to speak with each other. They adopt a binary language and form an in-vehicle network that must be precisely regulated. This was the aim for the inception of "Controller Area Network" protocol, also known as CAN bus [1] and is widespread today. It is standardised in ISO 11898-1:2015 [4] as a simple protocol based on two bus lines. However, it is not meant to be secure. Giampaolo Bella, Pietro Biondi, Gianpiero Costantino, Ilaria Matteucci |
WiSec | 4 |
| 2018 | CARS: Context Aware Reputation Systems to Evaluate Vehicles' BehaviourabstractThe introduction of new generation ICT systems into vehicles makes them highly connected with the external World. As drawback, vehicle becomes potentially vulnerable to security attacks. Here, we consider a scenario in which Vehicular Networks and a Urban Network work together to realize a defence mechanism based on Reputation Systems. In this way, we are able to identify and isolate possible malicious vehicles acting that could send messages with the aim of reducing the availability of the network. We propose Context Aware Reputation Systems, CARS, able to identify insider attackers and isolate them taking into account contextual conditions derived from sensors spread along the entire urban network. Then, we experimentally evaluate CARS on a real data-set of mobility traces of taxis in Rome to compare the proposed systems with existing ones that do not consider contextual conditions. The preliminary results obtained are promising and show the feasibility and potentiality of CARS. Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci, Antonia Bertolino, Antonello Calabrò, Eda Marchetti |
PDP | 3 |
| 2018 | Improving Vehicle Safety Through a Fog Collaborative InfrastructureabstractThe introduction of Information and Communication Technology in modern cities enhances quality, performance, and interactivity of urban services. The ultimate goal is twofold: the reduction of costs and of resource consumption and the increasing number of services offered to citizens. As drawback, smart cities become more vulnerable from the point of view of safety, security, and preservation of citizen privacy. In this paper, we propose a fog-computing based infrastructure to manage the sharing of information among vehicles and smart traffic lights in a urban network, with the aim of improving the safety of end-users of the network. For this purpose, our infrastructure provides to drivers several services to retrieve information in a private and secure way. The services we consider, are mainly four and are oriented to the traffic prediction, incident prevention, managing of emergency, and driver recognition. Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci, Francesco Mercaldo |
SMARTCOMP | 3 |
| 2018 | CANDY: A Social Engineering Attack to Leak Information from Infotainment SystemabstractThe introduction of Information and Communications Technologies (ICT) systems into vehicles make them more prone to cyber-security attacks that may impact of vehicles capability and, consequently, on the safety of drivers, passengers. In this paper, we focus on how to exploit security vulnerabilities affecting user-to-vehicle and intra- vehicle communications to hack the infotainment system to retrieve information about both vehicle and driver. Indeed, we designed and developed CANDY, a set of malicious APP injecting in a genuine Android APP, acting as a Trojan-horse on the Android In-Vehicle infotainment system. It opens a back-door that allows an attacker to remotely access to the infotainment system. We use this back-door to hit the privacy of the driver by recording her voice and collect information circulating on the CAN bus about the vehicle. CANDY is distributed by using social engineering techniques. Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Ilaria Matteucci |
VTC Spring | 4 |
| 2018 | Towards a Declarative Approach to Stateful and Stateless Usage Control for Data Protection
Francesco Di Cerbo, Fabio Martinelli, Ilaria Matteucci, Paolo Mori |
WEBIST | 3 |
| 2018 | Risk analysis of Android applications: A user-centric solution
Gianluca Dini, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi, Andrea Saracino, Daniele Sgandurra |
Future Gener. Comput. Syst. | 3 |
| 2018 | A tour of secure software engineering solutions for connected vehicles
Antonia Bertolino, Antonello Calabrò, Felicita Di Giandomenico, Giuseppe Lami, Francesca Lonetti, Eda Marchetti, Fabio Martinelli, Ilaria Matteucci, Paolo Mori |
Softw. Qual. J. | 8 |
| 2017 | Reputation Systems to Mitigate DoS Attack in Vehicular Network
Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci |
CRITIS | 3 |
| 2017 | Analysis of Data Sharing Agreements
Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi |
ICISSP | 3 |
| 2017 | A Quantitative Partial Model-Checking Function and Its OptimisationabstractPartial Model-Checking (PMC) is an efficient tool to reduce the combinatorial explosion of a state-space, arising in the verification of loosely-coupled software systems. At the same time, it is useful to consider quantitative temporal-modalities. This allows for checking whether satisfying such a desired modality is too costly, by comparing the final score consisting of how much the system spends to satisfy the policy, to a given threshold. We stir these two ingredients together in order to provide a Quantitative PMC function (QPMC), based on the algebraic structure of semirings. We design a method to extract part of the weight during QPMC, with the purpose to avoid the evaluation of a modality as soon as the threshold is crossed. Moreover, we extend classical heuristics to be quantitative, and we investigate the complexity of QPMC. Keyword: Partial Model Checking, Semirings, Optimisation, Quantitative Modal Logic Quantitative Process Algebra, Quantitative Evaluation of Systems. Stefano Bistarelli, Fabio Martinelli, Ilaria Matteucci, Francesco Santini 0001 |
LPAR | 3 |
| 2017 | Concurrent History-based Usage Control Policies
Fabio Martinelli, Ilaria Matteucci, Paolo Mori, Andrea Saracino |
MODELSWARD | 2 |
| 2015 | 1st International Workshop on TEchnical and LEgal aspects of data pRIvacy and Security (TELERISE 2015)abstractThis paper is the report on the 1st International Workshop on TEchnical and LEgal aspects of data pRIvacy and SEcurity (TELERISE 2015) at the 37th International Conference on Software Engineering (ICSE 2015). TELERISE investigates privacy and security issues in data sharing from a technical and legal perspective. Keynote speech as well as selected papers presented at the event fit the topics of the workshop. This report gives the rationale of TELERISE and it provides a provisional program. Ilaria Matteucci, Paolo Mori, Marinella Petrocchi |
ICSE (2) | 1 |
| 2014 | An Expertise-Driven Authoring Tool for E-Health Data PoliciesabstractData sharing is crucial in many aspects of nowadays life, from economy to leisure, from public administration to healthcare. However, it implies several privacy issues that have to be managed. Definition of appropriate policies helps to safeguard the data privacy. This paper describes an expertise-driven authoring tool for privacy policies to be applied to the healthcare scenario. The tool exhibits two different interfaces, designed according to specific expertise of the policy authors. It is part of a general framework for editing, analysis, and enforcement of privacy policies. Furthermore, this serves as a first brick for a usability study on such tools. Riccardo Conti, Ilaria Matteucci, Paolo Mori, Marinella Petrocchi |
CBMS | 2 |
| 2014 | Maturity Assessment of Wikipedia Medical ArticlesabstractRecent studies report that Internet users are growingly looking for health information through the Wikipedia Medicine Portal, a collaboratively edited multitude of articles with contents often comparable with professionally edited material. Automatic quality assessment of the Wikipedia medical articles has not received much attention by Academia and it presents open distinctive challenges. In this paper, we propose to tag the medical articles on the Wikipedia Medicine Portal, clearly stating their maturity degree, intended as a summarizing measure of several article properties. For this purpose, we adopt the Analytic Hierarchy Process, a well known methodology for decision making, and we evaluate the maturity degree of more than 24000 Wikipedia medical articles. The obtained results show how the qualitative analysis of medical content not always overlap with a quantitative analysis (an example of which is shown in the paper), since important properties of an article can hardly be synthesized by quantitative features. This seems particularly true when the analysis considers the concept of maturity, defined and verified in this work. Riccardo Conti, Emanuel Marzini, Angelo Spognardi, Ilaria Matteucci, Paolo Mori, Marinella Petrocchi |
CBMS | 4 |
| 2013 | Automated Synthesis and Ranking of Secure BPMN OrchestratorsabstractWe describe a formal methodology for the automatic synthesis of a secure orchestrator for a set of BPMN processes. The synthesized orchestrator is able to guarantee that all the processes that are started reach their end, and the resulting orchestrator process is secure, that is, it does not allow discloure of certain secret messages. In this work we present an implementation of a forth and back translation from BPMN to crypto-CCS, in such a way to exploit the PaMoChSA tool for synthesizing orchestrators. Furthermore, we study the problem of ranking orchestrators based on quantitative valuations of a process, and on the temporal evolution of such valuations and their security, as a function of the knowledge of the attacker. Vincenzo Ciancia, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi, José Antonio Martín, Ernesto Pimentel 0001 |
ARES | 3 |
| 2013 | A prototype for solving conflicts in XACML-based e-Health policiesabstractThe Electronic Patient Record (EPR) enables the sharing of medical documents among several and widespread healthcare organizations. To guarantee privacy properties, access control policies should be defined, regulating how the documents can be shared. Conflicts may occur among policies applicable to the same access request. We present a running prototype, based on an XACML engine, that implements a conflict resolution strategy as an extension to the standard combining algorithms of the XACML engine. We evaluate the efficiency of our proposal in terms of execution time, on a variable number of conflicting rules. Alessio Lunardelli, Ilaria Matteucci, Paolo Mori, Marinella Petrocchi |
CBMS | 2 |
| 2012 | A framework for automatic generation of security controllerabstractSUMMARY This paper concerns the study, the development and the synthesis of mechanisms for guaranteeing the security of complex systems, i.e. systems composed of several interacting components. A complex system under analysis is described as an open system, i.e. a system in which an unspecified component (a component whose behaviour is not fixed in advance) interacts with the known part of the system. Within this formal approach, we propose techniques that aim at synthesize controller programs able to guarantee that, for all possible behaviours of the unspecified component, the system should work properly, e.g. it should be able to satisfy a certain property. For performing this task, we first need to identify the set of necessary and sufficient conditions that the unspecified component has to satisfy in order to ensure that the whole system is secure. Hence, by exploiting the satisfiability procedures for temporal logic, we automatically synthesize an appropriate controller program that forces the unspecified component to meet these conditions. This will ensure the security of the whole system. In particular, we contribute within the area of the enforcement of security properties by proposing a flexible and automated framework that goes beyond the definition of how a system should behave to work properly. Indeed, while the majority of the related work focuses on the definition of monitoring mechanisms, we also address the synthesis problem. Moreover, we describe a tool for the synthesis of secure systems which is able to generate appropriate controller programs. This tool is also able to translate the synthesized controller programs into the ConSpec language. ConSpec programs can be actually deployed for enforcing security policies on mobile Java applications by using the run‐time framework developed in the ambit of the European Project S3MS. Copyright © 2010 John Wiley & Sons, Ltd. Fabio Martinelli, Ilaria Matteucci |
Softw. Test. Verification Reliab. | 2 |
| 2010 | Extending Security-by-Contract with Quantitative Trust on Mobile DevicesabstractSecurity-by-Contract (S×C) is a paradigm providing security assurances for mobile applications. In this work, we present an extension of S×C enriched with an automatic trust management infrastructure. Indeed, we enhance the already existing architecture by adding new modules and configurations for contracts managing. At deploy-time, our system decides the run-time configuration depending on the credentials of contract provider. Roughly, the run-time environment can both enforce a security policy and monitor the declared contract. According to the actual behaviour of the running program our architecture updates the trust level associated with the contract provider. The main advantage of this method is an automatic management of the level of trust of software and contract releasers. Gabriele Costa 0001, Nicola Dragoni, Aliaksandr Lazouski, Fabio Martinelli, Fabio Massacci, Ilaria Matteucci |
CISIS | 6 |
| 2008 | Synthesis of Local Controller Programs for Enforcing Global Security PropertiesabstractIn this paper we present a framework based on contexts theory and logic to study how, given a partially specified system, i.e., a system in which there are some unspecified/ unknown components, i.e., potential attackers, it is possible to enforce a global security property by controlling all the unspecified parts of the given system. We propose two methods to control them: A centralized method, in which there is a unique controller program that controls all the unspecified components, and a decentralized one in which each unspecified component is monitored by a controller program that forces it to behave correctly, i.e., according to a local requirement found by a reduction of the global one. In both cases we show how to synthesize controller programs that solve the problem. Fabio Martinelli, Ilaria Matteucci |
ARES | 2 |
| 2008 | A Framework for Contract-Policy Matching Based on Symbolic Simulations for Securing Mobile Device Application
Paolo Greci, Fabio Martinelli, Ilaria Matteucci |
ISoLA | 3 |
| 2008 | Controlling Usage in Business Process Workflows through Fine-Grained Security Policies
Benjamin Aziz, Álvaro Enrique Arenas, Fabio Martinelli, Ilaria Matteucci, Paolo Mori |
TrustBus | 4 |