VLDB 2026 Research / reviewers in the wild / expert
Mauro Andreolini
dblp:a/MauroAndreolini
· DBLP profile ↗
23ranked-venue papers
12as first author
6since 2021 · last 2026
0000-0003-3671-6927ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 6 · 3 first-author · 1 since 2021Security and privacy · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-authorComputer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Practical and secure history-independent indexing for queryable-encrypted databasesabstractQueryable encryption denotes a class of techniques which enable efficient query processing on encrypted databases, but may be affected by severe leakage if associated with improper indexes for achieving sublinear times in single-round query protocols. In this paper, we present an indexing data structure based on skip lists which does not introduce any additional leakage than the order of encrypted records: our index is history-independent, does not leak duplicates, is optimized for external-memory and range queries, and operates with a stateless client, making it well-suited for deployment in real-world databases. Previous works use no indexes or multi-round protocols, possibly with stateful clients, to achieve best security, but affect performance and alter the setting of existing databases, thus limiting deployability. Otherwise, they adopt standard indexes already available within the database at the cost of affecting security guarantees, or design in-memory data structures which do not suit database contexts. We demonstrate the practicality of our index by developing a prototype extension for PostgreSQL and for Order Revealing Encryption, which achieves performance that is comparable to the standard balanced tree implementation for up to 1M records, and acceptable overhead for encrypted data when scaling to 10M records. Mattia Trabucco, Mauro Andreolini, Luca Ferretti |
J. Inf. Secur. Appl. | 2 |
| 2025 | Player infrastructure for Attack and Defense Capture The Flag CompetitionsabstractIn learning the art of cybersecurity, Capture The Flag (CTF) competitions are a widely used tool, as they provide a rewarding gamification framework for the learner. In particular, in Attack and Defense CTFs each team is responsible for managing an infrastructure both in terms of defending its own and attacking the infrastructure of other teams. This means that attacking and defensive skills can be trained simultaneously. However, approaching this type of challenges is difficult for newcomers, since a fairly complicated player infrastructure is required for a team to participate properly. In this paper, we present an open source player side infrastructure that has been used in such competitions. It enables the automatic setup of all essential services for common blue teaming activities, such as packet inspection and request filtering rules. It also provides all of the mechanisms related to automating the launch of exploits against other competitors. Moreover, a mechanism for offloading computationally intensive task to an external machine (known as a support box) was implemented to overcome the hardware limitations of virtual machines provided by the organizers in these scenarios. Finally, we evaluate the proposed infrastructure under realistic workloads. Andrea Artioli, Edoardo Torrini, Francesco Mecatti, Mauro Andreolini |
NCA | 5 |
| 2025 | Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial AttacksabstractGraph Neural Networks (GNNs) represent a promising solution for Machine Learning (ML) based Network Intrusion Detection Systems (NIDS), thanks to their ability to leverage both network flow features and topological patterns. While GNN classifiers demonstrate superior robustness against feature-based adversarial attacks compared to other ML detectors, they remain vulnerable to structural adversarial attacks, where an attacker perturbs the underlying network graph topology by injecting edges or inserting nodes. Such attacks pose a realistic and severe threat, undermining the reliability of GNN-based NIDS in practical deployments. While countermeasures have been proposed in the literature, they often rely on assumptions that are unrealistic in real-world cybersecurity scenarios. In this paper, we propose a defense framework based on adversarial training to strengthen GNN-based NIDS against structural attacks. We generate adversarial samples by strategically replacing the source and destination nodes in benign network flows, thereby efficiently mimicking edge injection attacks. We evaluate our approach on two widely used datasets (CTU-13 and TON-IoT) using EGraphSAGE as the base GNN classifier. Experimental results show that our approach produces hardened detectors with superior detection performance on clean graphs and enhanced robustness against structural adversarial attacks. Dimitri Galli, Andrea Venturi, Dario Stabili, Mauro Andreolini, Mirco Marchetti |
NCA | 4 |
| 2024 | Effects of Geohashing and K-Means Clustering on Uniqueness in a Mobility DatasetabstractIn the era of ubiquitous computing, the collection of users' geographical location is increasingly widespread. This represents an enabling technology, capable of creating new type of services but at the same time represents a new digital asset that needs to be protected in order to safeguard the users' privacy. In fact, exploiting everyday movements, it is possible for a threat actor to gather sensible information about the victims that can be leveraged afterwards. In this preliminary paper, we reproduced some major results in the field of re-identification of users' trajectories, validating them under scenarios where different countermeasures for geographical data are in place. Specifically, we tested generalization of spatial data using geohashing and K-means clustering. The results were obtained using a dataset that collects users from all over the world, allowing the clustering methods to range on very different scales. Results shows that, even if a strong data generalization is applied, users' trajectories keep their uniqueness, showing high re-identification ratios. Nevertheless, the usability issues typical of these techniques are still present, having only few tens of points for covering the entire globe which cannot be considered a general solution for every possible use case of such data. Andrea Artioli, Luca Bedogni, Mauro Andreolini |
SEC | 3 |
| 2023 | DOLOS: A Novel Architecture for Moving Target DefenseabstractMoving Target Defense and Cyber Deception emerged in recent years as two key proactive cyber defense approaches, contrasting with the static nature of the traditional reactive cyber defense. The key insight behind these approaches is to impose an asymmetric disadvantage for the attacker by using deception and randomization techniques to create a dynamic attack surface. Moving Target Defense (MTD) typically relies on system randomization and diversification, while Cyber Deception is based on decoy nodes and fake systems to deceive attackers. However, current Moving Target Defense techniques are complex to manage and can introduce high overheads, while Cyber Deception nodes are easily recognized and avoided by adversaries. This paper presents DOLOS, a novel architecture that unifies Cyber Deception and Moving Target Defense approaches. DOLOS is motivated by the insight that deceptive techniques are much more powerful when integrated into production systems rather than deployed alongside them. DOLOS combines typical Moving Target Defense techniques, such as randomization, diversity, and redundancy, with cyber deception and seamlessly integrates them into production systems through multiple layers of isolation. We extensively evaluate DOLOS against a wide range of attackers, ranging from automated malware to professional penetration testers, and show that DOLOS is effective in slowing down attacks and protecting the integrity of production systems. We also provide valuable insights and considerations for the future development of MTD techniques based on our findings. Giulio Pagnotta, Fabio De Gaspari, Dorjan Hitaj, Mauro Andreolini, Michele Colajanni, Luigi V. Mancini |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Survivable zero trust for cloud computing environments
Luca Ferretti, Federico Magnanini, Mauro Andreolini, Michele Colajanni |
Comput. Secur. | 3 |
| 2020 | A Framework for the Evaluation of Trainee Performance in Cyber Range Exercises
Mauro Andreolini, Vincenzo Giuseppe Colacino, Michele Colajanni, Mirco Marchetti |
Mob. Networks Appl. | 1 |
| 2020 | Deep Reinforcement Adversarial Learning Against Botnet Evasion AttacksabstractAs cybersecurity detectors increasingly rely on machine learning mechanisms, attacks to these defenses escalate as well. Supervised classifiers are prone to adversarial evasion, and existing countermeasures suffer from many limitations. Most solutions degrade performance in the absence of adversarial perturbations; they are unable to face novel attack variants; they are applicable only to specific machine learning algorithms. We propose the first framework that can protect botnet detectors from adversarial attacks through deep reinforcement learning mechanisms. It automatically generates realistic attack samples that can evade detection, and it uses these samples to produce an augmented training set for producing hardened detectors. In such a way, we obtain more resilient detectors that can work even against unforeseen evasion attacks with the great merit of not penalizing their performance in the absence of specific attacks. We validate our proposal through an extensive experimental campaign that considers multiple machine learning algorithms and public datasets. The results highlight the improvements of the proposed solution over the state-of-the-art. Our method paves the way to novel and more robust cybersecurity detectors based on machine learning applied to network traffic analytics. Giovanni Apruzzese, Mauro Andreolini, Mirco Marchetti, Andrea Venturi, Michele Colajanni |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2018 | A symmetric cryptographic scheme for data integrity verification in cloud databases
Luca Ferretti, Mirco Marchetti, Mauro Andreolini, Michele Colajanni |
Inf. Sci. | 3 |
| 2015 | A collaborative framework for intrusion detection in mobile networks
Mauro Andreolini, Michele Colajanni, Mirco Marchetti |
Inf. Sci. | 1 |
| 2015 | Adaptive, scalable and reliable monitoring of big data on clouds
Mauro Andreolini, Michele Colajanni, Marcello Pietri, Stefania Tosi |
J. Parallel Distributed Comput. | 1 |
| 2014 | Monitoring Large Cloud-Based SystemsabstractLarge scale cloud-based services are built upon a multitude of hardware and software resources, disseminated in one or multiple data centers.Controlling and managing these resources requires the integration of several pieces of software that may yield a representative view of the data center status.Today's both closed and open-source monitoring solutions fail in different ways, including the lack of scalability, scarce representativity of global state conditions, inability in guaranteeing persistence in service delivery, and the impossibility of monitoring multi-tenant applications.In this paper, we present a novel monitoring architecture that addresses the aforementioned issues.It integrates a hierarchical scheme to monitor the resources in a cluster with a distributed hash table (DHT) to broadcast system state information among different monitors.This architecture strives to obtain high scalability, effectiveness and resilience, as well as the possibility of monitoring services spanning across different clusters or even different data centers of the cloud provider.We evaluate the scalability of the proposed architecture through a bottleneck analysis achieved by experimental results. Mauro Andreolini, Marcello Pietri, Stefania Tosi, Andrea Balboni |
CLOSER | 1 |
| 2013 | Real-time adaptive algorithm for resource monitoringabstractIn large scale systems, real-time monitoring of hardware and software resources is a crucial means for any management purpose. In architectures consisting of thousands of servers and hundreds of thousands of component resources, the amount of data monitored at high sampling frequencies represents an overhead on system performance and communication, while reducing sampling may cause quality degradation. We present a real-time adaptive algorithm for scalable data monitoring that is able to adapt the frequency of sampling and data updating for a twofold goal: to minimize computational and communication costs, to guarantee that reduced samples do not affect the accuracy of information about resources. Experiments carried out on heterogeneous data traces referring to synthetic and real environments confirm that the proposed adaptive approach reduces utilization and communication overhead without penalizing the quality of data with respect to existing monitoring algorithms. Mauro Andreolini, Michele Colajanni, Marcello Pietri, Stefania Tosi |
CNSM | 1 |
| 2012 | Improving application responsiveness with the BFQ disk I/O schedulerabstractBFQ (Budget Fair Queueing) is a production-quality, proportional-share disk scheduler with a relatively large user base. Part of its success is due to a set of simple heuristics that we added to the original algorithm about one year ago. These heuristics are the main focus of this paper. Paolo Valente, Mauro Andreolini |
SYSTOR | 2 |
| 2011 | Dynamic Request Management Algorithms for Web-Based Services in Cloud ComputingabstractProviders of Web-based services can take advantage of many convenient features of cloud computing infrastructures, but they still have to implement request management algorithms that are able to face sudden peaks of requests. We consider distributed algorithms implemented by front-end servers to dispatch and redirect requests among application servers. Current solutions based on load-blind algorithms, or considering just server load and thresholds are inadequate to cope with the demand patterns reaching modern Internet application servers. In this paper, we propose and evaluate a request management algorithm, namely Performance Gain Prediction, that combines several pieces of information (server load, computational cost of a request, user session migration and redirection delay) to predict whether the redirection of a request to another server may result in a shorter response time. To the best of our knowledge, no other study combines information about infrastructure status, user request characteristics and redirection overhead for dynamic request management in cloud computing. Our results show that the proposed algorithm is able to reduce the response time with respect to existing request management algorithms operating on the basis of thresholds. Riccardo Lancellotti, Mauro Andreolini, Claudia Canali, Michele Colajanni |
COMPSAC | 2 |
| 2009 | A flexible and robust lookup algorithm for P2P systemsabstractOne of the most critical operations performed in a P2P system is the lookup of a resource. The main issues to be addressed by lookup algorithms are: (1) support for flexible search criteria (e.g., wildcard or multi-keyword searches), (2) effectiveness - i.e., ability to identify all the resources that match the search criteria, (3) efficiency - i.e. low overhead, (4) robustness with respect to node failures and churning. Flood-based P2P networks provide flexible lookup facilities and robust performance at the expense of high overhead, while other systems (e.g. DHT) provide a very efficient lookup mechanism, but lacks flexibility. In this paper, we propose a novel resource lookup algorithm, namely fuzzy-DHT, that solves this trade-off by introducing a flexible and robust lookup criteria based on multiple keywords on top of a distributed hash table algorithm. We demonstrate that the fuzzy-DHT algorithm satisfies all the requirements of P2P lookup systems combining the flexibility of flood-based mechanisms while preserving high efficiency, effectiveness ad robustness. Mauro Andreolini, Riccardo Lancellotti |
IPDPS | 1 |
| 2008 | Runtime Prediction Models for Internet-based Systems
Sara Casolari, Mauro Andreolini, Michele Colajanni |
MASCOTS | 2 |
| 2008 | Models and framework for supporting runtime decisions in Web-based systemsabstractEfficient management of distributed Web-based systems requires several mechanisms that decide on request dispatching, load balance, admission control, request redirection. The algorithms behind these mechanisms typically make fast decisions on the basis of the load conditions of the system resources. The architecture complexity and workloads characterizing most Web-based services make it extremely difficult to deduce a representative view of a resource load from collected measures that show extreme variability even at different time scales. Hence, any decision based on instantaneous or average views of the system load may lead to useless or even wrong actions. As an alternative, we propose a two-phase strategy that first aims to obtain a representative view of the load trend from measured system values and then applies this representation to support runtime decision systems. We consider two classical problems behind decisions: how to detect significant and nontransient load changes of a system resource and how to predict its future load behavior. The two-phase strategy is based on stochastic functions that are characterized by a computational complexity that is compatible with runtime decisions. We describe, test, and tune the two-phase strategy by considering as a first example a multitier Web-based system that is subject to different classes of realistic and synthetic workloads. Also, we integrate the proposed strategy into a framework that we validate by applying it to support runtime decisions in a cluster Web system and in a locally distributed Network Intrusion Detection System. Mauro Andreolini, Sara Casolari, Michele Colajanni |
ACM Trans. Web | 1 |
| 2007 | Trend-based Load Balancer for a Multi-tier Distributed SystemabstractThe unexpected and continuous changes of the workload reaching any Internet-based service make really difficult to guarantee a balanced utilization of the server resources. In this paper, we propose a novel class of state-aware dispatching algorithms that take into account not only the present resource load but also the behavioral trend of the server load, that is, whether it is increasing, decreasing or oscillating. We apply one algorithm of this class to a multitier Web-based system and demonstrate that it is able to improve load balancing of the most critical server resources. Mauro Andreolini, Sara Casolari, Michele Colajanni |
MASCOTS | 1 |
| 2007 | Dynamic load balancing for network intrusion detection systems based on distributed architecturesabstractIncreasing traffic and the necessity of stateful analyses impose strong computational requirements on network intrusion detection systems (NIDS), and motivate the need of distributed architectures with multiple sensors. In a context of high traffic with heavy tailed characteristics, static rules for dispatching traffic slices among distributed sensors cause severe imbalance. Hence, the distributed NIDS architecture must be combined with adequate mechanisms for dynamic load redistribution. In this paper, we propose and compare different policies for the activation/deactivation of the dynamic load balancer. In particular, we consider and compare single vs. double threshold schemes, and load representations based on resource measures vs. load aggregation models. Our experimental results show that the best combination of a double threshold scheme with a linear aggregation of resource measures is able to achieve a really satisfactory balance of the sensor loads together with a sensible reduction of the number of load balancer activations. Mauro Andreolini, Sara Casolari, Michele Colajanni, Mirco Marchetti |
NCA | 1 |
| 2007 | Impact of request dispatching granularity in geographically distributed Web systemsabstractThe advent of the mobile Web and the increasing demand for personalized contents arise the need for computationally expensive services, such as dynamic generation and on-the- fly adaptation of contents. Providing these services exacerbates the performance issues that have to be addressed by the underlying Web architecture. When performance issues are addressed through geographically distributed Web systems with a large number of nodes located on the network edge, the dispatching mechanism that distributes requests among the system nodes becomes a critical element. In this paper, we investigate how the granularity of re- quest dispatching may affect the performance of a distributed Web system for personalized contents. Through a real prototype, we compare dispatching mechanisms operating at various levels of granularity for different workload and network scenarios. We demonstrate that the choice of the best granularity for request dispatching strongly depends on the characteristics of the workload in terms of heterogeneity and computational requirements. A coarse- grain dispatching is preferable only when the requests have similar computational requirements. In all other instances of skewed workloads, that we can consider more realistic, a fine-grain dispatching augments the control on the node load and allows the system to achieve better performance. Mauro Andreolini, Claudia Canali, Riccardo Lancellotti |
NCA | 1 |
| 2006 | A Distributed Architecture for Gracefully Degradable Web-Based ServicesabstractModern Web sites provide multiple services that are often deployed through distributed architectures. The importance and the economic impact of Web-based services introduces significant requirements in terms of performance and quality of service. In this paper, we propose an access control mechanism for dynamic, Web-based systems. The proposed architecture takes into account two goals: the service of all requests pertaining to an admitted session until system saturation, and a graceful, controlled degradation of performance in case of overwhelming user request loads. The session-oriented behavior is obtained through an admission control mechanism that denies access to requests starting new sessions if the system is judged as overloaded. Graceful degradation is achieved through the refusal of single requests with increasing priority. Static priorities, determined for example, by the user category (guest, member, gold) are taken into account first. If the system is still in overload, the access control mechanism evaluates dynamically the popularity of single requests, and drops the least popular requests Mauro Andreolini, Sara Casolari, Michele Colajanni |
NCA | 1 |
| 2003 | Kernel-based Web switches providing content-aware routingabstractLocally distributed Web server systems represent a cost-effective solution to the performance problems due to high traffic volumes reaching popular Web sites. In this paper we focus on architectures based on layer-7 Web switches because they allow a much richer set of possibilities for the Web site architecture, at the price of a scalability much lower than that provided by a layer-4 switch. In this paper we compare the performance of three solutions for layer-7 Web switch: a two-way application-layer architecture, a two-way kernel-based architecture, and a one-way kernel-based architecture. We show quantitatively how much better the one-way architecture performs with respect to a two-way scheme, even if implemented at the kernel level. We conclude that an accurate implementation of a layer-7 Web switch may become a viable solution to the performance requirements of the majority of cluster-based information systems. Mauro Andreolini, Michele Colajanni, Marcello Nuccio |
NCA | 1 |