Emmanuele Zambon

dblp:z/EmmanueleZambon · DBLP profile ↗
← Back
17ranked-venue papers
1as first author
7since 2021 · last 2025
0000-0002-8079-4087ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 7 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Ruling the Unruly: Designing Effective, Low-Noise Network Intrusion Detection Rules for Security Operations Centers
abstract
Many Security Operations Centers (SOCs) today still heavily rely on signature-based Network Intrusion Detection Systems (NIDS) such as Suricata. The specificity of intrusion detection rules and the coverage provided by rulesets are common concerns within the professional community surrounding SOCs, which impact the effectiveness of automated alert post-processing approaches. We postulate a better understanding of factors influencing the quality of rules can help address current SOC issues. In this paper, we characterize the rules in use at a collaborating commercial (managed) SOC serving customers in sectors including education and IT management. During this process, we discover six relevant design principles, which we consolidate through interviews with experienced rule designers at the SOC.We then validate our design principles by quantitatively assessing their effect on rule specificity. We find that several of these design considerations significantly impact unnecessary workload caused by rules. For instance, rules that leverage proxies for detection, and rules that do not employ alert throttling or do not distinguish (un)successful malicious actions, cause significantly more workload for SOC analysts. Moreover, rules that match a generalized characteristic to detect malicious behavior, which is believed to increase coverage, also significantly increase workload, suggesting a tradeoff must be struck between rule specificity and coverage. We show that these design principles can be applied successfully at a SOC to reduce workload whilst maintaining coverage despite the prevalence of violations of the principles.
Koen T. W. Teuwen, Tom Mulders, Emmanuele Zambon, Luca Allodi
AsiaCCS3
2025 POSTER: SuriCap - A Measurement Platform to Study and Evaluate Intrusion Detection Rule Engineering
abstract
Organizations deploy Intrusion Detection Systems (IDSs) like Suricata to defend against threats. Although rulesets, rules, and the resulting alerts have been studied previously, little is known about the process by which rules are engineered thus far. We aim to address the previously mentioned gaps by studying how network intrusion detection rules are derived from incidents. To this end, we propose the SuriCap measurement platform and organize Jeopardy-style workshops in which participants compete to engineer Suricata rules. We collect a rich dataset consisting of over 364 rules from 28 participants. Preliminary results suggest our experimental design is viable and, together with the SuriCap measurement platform, can enable us to answer several research questions surrounding the engineering process of network intrusion detection rules.
Koen T. W. Teuwen, Emmanuele Zambon, Luca Allodi
AsiaCCS2
2024 A Security Alert Investigation Tool Supporting Tier 1 Analysts in Contextualizing and Understanding Network Security Events
abstract
The investigations run by tier 1 (T1) analysts in a Security Operation Center are critical to the SOC operations as they represent the first gateway to alert escalation and incident response. Critically, they demand an accurate and as-complete-as-possible understanding of the events surrounding the investigated alert. This is a complex task inexperienced T1 analysts can easily lose track of. In this work, we collaborate with a commercial SOC to develop an alert investigation support tool to help inexperienced analysts identify and collect all the information relevant to the investigation of an alert. We evaluate the prototype tool with two qualitative studies. The first study employs T1 analysts from the SOC to evaluate the conformity of the tool to the underpinning analysis process. The second study employs 57 students, recruited from the same pool where the SOC acquires its junior analysts from, to evaluate whether it helps inexperienced analysts develop a complete understanding of events surrounding security alert data. Our findings suggest that employing the tool helps inexperienced analysts form a more accurate understanding of attacks, at no time cost. We discuss the wider implications for research and practice.
Leon Kersten, Santiago Darré, Tom Mulders, Emmanuele Zambon, Marco Caselli, Chris Snijders 0001, Luca Allodi
ACSAC4
2024 From Power to Water: Dissecting SCADA Networks Across Different Critical Infrastructures
Neil Ortiz Silva, Martin Rosso, Emmanuele Zambon, Jerry den Hartog, Alvaro A. Cárdenas
PAM (1)3
2024 A Tale of Two Industroyers: It was the Season of Darkness
abstract
In this paper, we study two pieces of malware that attempted to create blackouts in Ukraine. In particular, we design and develop a new sandbox that emulates different networks, devices, and other characteristics so that we can execute malware targeting substation equipment and understand in detail the specific sequence of actions the attackers could perform on substation equipment. We also study the effects that future similar malware can have. Our findings include new malware behavior not previously documented (such as the detailed algorithm for the MMS protocol payload) and an illustration of how attacking different targets will produce different effects.
Luis E. Salazar, Sebastián R. Castro, Juan Lozano, Keerthi Koneru, Emmanuele Zambon, Ross Baldick, Marina Krotofil, Alonso Rojas, Alvaro A. Cárdenas
SP5
2023 ICSvertase: A Framework for Purpose-based Design and Classification of ICS Honeypots
abstract
As attacks on Industrial Control Systems (ICS) are increasing, the design and deployment of ICS honeypots is gaining momentum as a way to prevent, detect, and research them. However, ICS honeypot creators hardly explicitly consider what adversary behavior they want to capture, potentially creating honeypots that may not completely fulfill their intended purpose. At the same time, ICS honeypots are classified using the traditional interaction level scheme which is unsuitable for ICS due to its unique properties. In turn, these issues make it hard for potential users to systematically determine the suitability of an ICS honeypot for their use case. To tackle these problems, in this paper we introduce ICSvertase, a novel framework allowing for structural reasoning about ICS honeypots. ICSvertase integrates several existing components from the ATT&CK for ICS and Engage frameworks provided by MITRE and extends them with novel elements. ICSvertase provides a novel approach to helping companies and users in several real-world use cases, such as choosing the most suitable existing ICS honeypot, designing new ICS honeypots, and classifying existing ones in a more fine-grained way. To show ICSvertase’s benefits, we provide examples for these real-world use cases and compare them to their traditional counterparts.
Stash Kempinski, Shuaib Ichaarine, Savio Sciancalepore, Emmanuele Zambon
ARES4
2023 'Give Me Structure': Synthesis and Evaluation of a (Network) Threat Analysis Process Supporting Tier 1 Investigations in a Security Operation Center
Leon Kersten, Tom Mulders, Emmanuele Zambon, Chris Snijders 0001, Luca Allodi
SOUPS3
2017 ECFI: Asynchronous Control Flow Integrity for Programmable Logic Controllers
abstract
Programmable Logic Controllers (PLCs) are a family of embedded devices that are being used to control physical processes in critical infrastructures. Similar to other embedded devices, PLCs are vulnerable to memory corruption and control-flow hijacking attacks. Because PLCs are being used for critical control applications, compromised PLCs constitute a significant security and safety risk.
Ali Abbasi 0002, Thorsten Holz, Emmanuele Zambon, Sandro Etalle
ACSAC3
2017 \mu Shield - Configurable Code-Reuse Attacks Mitigation For Embedded Systems
Ali Abbasi 0002, Jos Wetzels, Wouter Bokslag, Emmanuele Zambon, Sandro Etalle
NSS4
2016 Stealth Low-Level Manipulation of Programmable Logic Controllers I/O by Pin Control Exploitation
Ali Abbasi 0002, Majid Hashemi, Emmanuele Zambon, Sandro Etalle
CRITIS3
2016 Specification Mining for Intrusion Detection in Networked Control Systems
Marco Caselli, Emmanuele Zambon, Johanna Amann, Robin Sommer, Frank Kargl
USENIX Security Symposium2
2014 Through the eye of the PLC: semantic security monitoring for industrial processes
abstract
Off-the-shelf intrusion detection systems prove an ill fit for protecting industrial control systems, as they do not take their process semantics into account. Specifically, current systems fail to detect recent process control attacks that manifest as unauthorized changes to the configuration of a plant's programmable logic controllers (PLCs). In this work we present a detector that continuously tracks updates to corresponding process variables to then derive variable-specific prediction models as the basis for assessing future activity. Taking a specification-agnostic approach, we passively monitor plant activity by extracting variable updates from the devices' network communication. We evaluate the capabilities of our detection approach with traffic recorded at two operational water treatment plants serving a total of about one million people in two urban areas. We show that the proposed approach can detect direct attacks on process control, and we further explore its potential to identify more sophisticated indirect attacks on field device measurements as well.
Dina Hadziosmanovic, Robin Sommer, Emmanuele Zambon, Pieter H. Hartel
ACSAC3
2014 On Emulation-Based Network Intrusion Detection Systems
Ali Abbasi 0002, Jos Wetzels, Wouter Bokslag, Emmanuele Zambon, Sandro Etalle
RAID4
2013 On the Feasibility of Device Fingerprinting in Industrial Control Systems
Marco Caselli, Dina Hadziosmanovic, Emmanuele Zambon, Frank Kargl
CRITIS3
2012 N-Gram against the Machine: On the Feasibility of the N-Gram Network Analysis for Binary Protocols
Dina Hadziosmanovic, Lorenzo Simionato, Damiano Bolzoni, Emmanuele Zambon, Sandro Etalle
RAID4
2011 Model-based qualitative risk assessment for availability of IT infrastructures
abstract
For today’s organisations, having a reliable information system is crucial to safeguard enterprise revenues (think of on-line banking, reservations for e-tickets etc.). Such a system must often offer high guarantees in terms of its availability; in other words, to guarantee business continuity, IT systems can afford very little downtime. Unfortunately, making an assessment of IT availability risks is difficult: incidents affecting the availability of a marginal component of the system may propagate in unexpected ways to other more essential components that functionally depend on them. General-purpose risk assessment (RA) methods do not provide technical solutions to deal with this problem. In this paper we present the qualitative time dependency (QualTD) model and technique, which is meant to be employed together with standard RA methods for the qualitative assessment of availability risks based on the propagation of availability incidents in an IT architecture. The QualTD model is based on our previous quantitative time dependency (TD) model (Zambon et al. in BDIM ’07: Second IEEE/IFIP international workshop on business-driven IT management. IEEE Computer Society Press, pp 75–83, 2007), but provides more flexible modelling capabilities for the target of assessment. Furthermore, the previous model required quantitative data which is often too costly to acquire, whereas QualTD applies only qualitative scales, making it more applicable to industrial practice. We validate our model and technique in a real-world case by performing a risk assessment on the authentication and authorisation system of a large multinational company and by evaluating the results with respect to the goals of the stakeholders of the system. We also perform a review of the most popular standard RA methods and discuss which type of method can be combined with our technique.
Emmanuele Zambon, Sandro Etalle, Roel J. Wieringa, Pieter H. Hartel
Softw. Syst. Model.1
2010 CRAC: Confidentiality risk assessment and IT-infrastructure comparison
abstract
CRAC is an IT-infrastructure-based method for assessing and comparing confidentiality risks of distributed IT systems. The method determines confidentiality risks by taking into account the effects of the leakage of confidential information (e.g. industrial secrets), and the paths that may be followed by different attackers (e.g. insider and outsider). We evaluate its effectiveness by applying it to a real-world outsourcing case.
Ayse Morali, Emmanuele Zambon, Sandro Etalle, Roel J. Wieringa
CNSM2