VLDB 2026 Research / reviewers in the wild / expert
Stefano Zanero
dblp:z/StefanoZanero
· DBLP profile ↗
74ranked-venue papers
1as first author
29since 2021 · last 2026
0000-0003-4710-5283ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 63 · 23 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On the (In)Security of Loading Machine Learning ModelsabstractThe rise of model sharing through frameworks and dedicated hubs makes Machine Learning significantly more accessible. Despite its benefits, loading shared models exposes users to underexplored security risks, while security awareness remains limited among both practitioners and developers. To enable a more security-conscious approach in Machine Learning model sharing, in this paper, we evaluate the security posture of frameworks and hubs, assess whether security-oriented mechanisms offer real protection, and survey how users perceive the security narratives surrounding model sharing. Our evaluation shows that most frameworks and hubs address security risks partially at best, often by shifting responsibility to the user. More concerningly, our analysis of frameworks advertising security-oriented settings and complete model sharing uncovered multiple 0-day vulnerabilities enabling arbitrary code execution. Through this analysis, we show that, despite the recent narrative, securely loading Machine Learning models is far from being a solved problem and cannot be guaranteed by the file format used for sharing. Our survey shows that the security narrative leads users to consider security-oriented settings as trustworthy, despite the weaknesses shown in this work. From this, we derive suggestions to strengthen the security of model-sharing ecosystems. Gabriele Digregorio, Marco Di Gennaro 0001, Stefano Zanero, Stefano Longari, Michele Carminati |
SP | 3 |
| 2025 | Linux Hurt Itself in Its Confusion! Exploiting Out-of-Memory Killer for Confusion Attacks via Heuristic Manipulation
Lorenzo Bossi, Daniele Mammone, Michele Carminati, Stefano Zanero, Stefano Longari |
DIMVA (2) | 4 |
| 2025 | Poster: FedBlockParadox - A Framework for Simulating and Securing Decentralized Federated Learning
Gabriele Digregorio, Francesco Bleggi, Federico Caroli, Michele Carminati, Stefano Zanero, Stefano Longari |
DIMVA (2) | 5 |
| 2025 | PackHero: A Scalable Graph-Based Approach for Efficient Packer Identification
Marco Di Gennaro 0001, Mario D'Onghia, Mario Polino, Stefano Zanero, Michele Carminati |
DIMVA (2) | 4 |
| 2025 | How Stealthy is Stealthy? Studying the Efficacy of Black-Box Adversarial Attacks in the Real World
Francesco Panebianco, Mario D'Onghia, Stefano Zanero, Michele Carminati |
SEC (2) | 3 |
| 2025 | SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?
Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati, Stefano Zanero, Hodaya Binyamini, Gal Engelberg, Daniel Klein 0003, Giancarlo Guizzardi, Marco Caselli, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Thijs van Ede |
USENIX Security Symposium | 5 |
| 2025 | Evaluating the potential of quantum machine learning in cybersecurity: A case-study on PCA-based intrusion detection systems
Armando Bellante, Tommaso Fioravanti, Michele Carminati, Stefano Zanero, Alessandro Luongo |
Comput. Secur. | 4 |
| 2025 | TimberStrike: Dataset Reconstruction Attack Revealing Privacy Leakage in Federated Tree-Based SystemsabstractFederated Learning has emerged as a privacy-oriented alternative to centralized Machine Learning, enabling collaborative model training without direct data sharing. While extensively studied for neural networks, the security and privacy implications of tree-based models remain underexplored. This work introduces TimberStrike, an optimization-based dataset reconstruction attack targeting horizontally federated tree-based models. Our attack, carried out by a single client, exploits the discrete nature of decision trees by using split values and decision paths to infer sensitive training data from other clients. We evaluate TimberStrike on State-of-the-Art federated gradient boosting implementations across multiple frameworks, including Flower, NVFlare, and FedTree, demonstrating their vulnerability to privacy breaches. On a publicly available stroke prediction dataset, TimberStrike consistently reconstructs between 73.05% and 95.63% of the target dataset across all implementations. We further analyze Differential Privacy, showing that while it partially mitigates the attack, it also significantly degrades model performance. Our findings highlight the need for privacy-preserving mechanisms specifically designed for tree-based Federated Learning systems, and we provide preliminary insights into their design. Marco Di Gennaro 0001, Giovanni De Lucia, Stefano Longari, Stefano Zanero, Michele Carminati |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | Assessing the Resilience of Automotive Intrusion Detection Systems to Adversarial ManipulationabstractThe security of modern vehicles has become increasingly important, with the controller area network (CAN) bus serving as a critical communication backbone for various electronic control units (ECUs). The absence of robust security measures in CAN, coupled with the increasing connectivity of vehicles, makes them susceptible to cyberattacks. While intrusion detection systems (IDSs) have been developed to counter such threats, they are not foolproof. Adversarial attacks, particularly evasion attacks, can manipulate inputs to bypass detection by IDSs. This article extends our previous work by investigating the feasibility and impact of gradient-based adversarial attacks performed with different degrees of knowledge against automotive IDSs. We consider three scenarios: white-box (attacker with full system knowledge), grey-box (partial system knowledge), and—the more realistic—black-box (no knowledge of the IDS’s internal workings or data). We evaluate the effectiveness of the proposed attacks against state-of-the-art IDSs on two publicly available datasets. Additionally, we study the effect of the adversarial perturbation on the attack impact and evaluate real-time feasibility by precomputing evasive payloads for timed injection based on bus traffic. Our results demonstrate that, besides attacks being challenging due to the automotive domain constraints, their effectiveness is strongly dependent on the dataset quality, the target IDS, and the attacker’s degree of knowledge. Stefano Longari, Paolo Cerracchio, Michele Carminati, Stefano Zanero |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2025 | Highliner: Enhancing Binary Analysis through NLP-Based Instruction-Level Detection of C++ Inline FunctionsabstractThe complexities introduced by compiler optimization have long stood as a significant obstacle in binary analysis and reverse engineering. Function inlining, in particular, complicates function recognition by replacing function calls with the entire body of the callee, mixing code from multiple functions. State-of-the-art approaches can identify inlined functions at basic block granularity, but cannot determine which instructions belong to each function and precisely deduce inlined boundaries. Without this information, further analyses such as decompilation cannot be performed effectively. This paper presents Highliner, a novel approach that improves state-of-the-art approaches by identifying inline instances at instruction-level granularity. Highliner operates downstream of block-level detectors: given basic blocks reported by state-of-the-art approaches as belonging to a specific inlined function, it labels each instruction as Inlined or Not inlined and recovers the inlined-function boundaries. We treat the problem as a sequence tagging task typical of NLP and implement a learning-based technique involving instruction embedding and recurrent neural networks. We compile a dataset of open-source projects with different optimizations and use the DWARF debug information standard to construct labeled sequences of inline instructions. We use this dataset to train, validate, and test a sequence labeling architecture in which instructions are encoded via the pre-trained assembly language transformer PalmTree and then processed by an RNN-based classifier to produce binary predictions. When evaluated as a binary classifier, Highliner achieves an F1-score of 0.94 overall. In addition, when specifically tested on recognizing function boundaries, Highliner achieves an Accuracy of 0.82 on initial boundaries and 0.83 on final boundaries. Lorenzo Dall'Aglio, Lorenzo Binosi, Michele Carminati, Stefano Zanero, Mario Polino |
ACM Trans. Priv. Secur. | 4 |
| 2025 | Swarm: A Distributed Ledger-based Framework to Enhance Air Traffic Control Security Using ADS-B ProtocolabstractIn aviation, safety is paramount, with air traffic control (ATC) playing a crucial role in monitoring aircraft to prevent collisions and manage traffic flows. In response to increasing air traffic, a renewal process has been initiated. This includes deploying the automatic dependent surveillance-broadcast (ADS-B) communications protocol, which aims to enhance surveillance precision and increase the number of aircraft that can be handled simultaneously. This transition is transforming ATC from a radar-based system to a more advanced satellite-based global positioning system (GPS) location tracking system. However, due to its inherently open design, the ADS-B protocol lacks critical security features such as authentication, necessitating the adoption of additional security measures to mitigate potential cyber-attacks. To address these vulnerabilities, this work introduces Swarm, an innovative distributed ledger-based framework, built on top of the ADS-B protocol and aimed at enhancing the security of air traffic control (ATC) while avoiding single points of failure. Swarm can be integrated into existing ATC infrastructure without requiring any modifications to the ADS-B protocol. We evaluate Swarm through rigorous and realistic attack scenarios, using real-world aviation data, demonstrating its capability to enhance the security of the aviation domain. Gabriele Digregorio, Edoardo Saputelli, Stefano Longari, Michele Carminati, Stefano Zanero |
ACM Trans. Priv. Secur. | 5 |
| 2024 | The Illusion of Randomness: An Empirical Analysis of Address Space Layout Randomization ImplementationsabstractAddress Space Layout Randomization (ASLR) is a crucial defense mechanism employed by modern operating systems to mitigate exploitation by randomizing processes? memory layouts. However, the stark reality is that real-world implementations of ASLR are imperfect and subject to weaknesses that attackers can exploit. This work evaluates the effectiveness of ASLR on major desktop platforms, including Linux, MacOS, and Windows, by examining the variability in the placement of memory objects across various processes, threads, and system restarts. In particular, we collect samples of memory object locations, conduct statistical analyses to measure the randomness of these placements and examine the memory layout to find any patterns among objects that could decrease this randomness. The results show that while some systems, like Linux distributions, provide robust randomization, others, like Windows and MacOS, often fail to adequately randomize key areas like executable code and libraries. Moreover, we find a significant entropy reduction in the entropy of libraries after the Linux 5.18 version and identify correlation paths that an attacker could leverage to reduce exploitation complexity significantly. Ultimately, we rank the identified weaknesses based on severity and validate our entropy estimates with a proof-of-concept attack. In brief, this paper provides the first comprehensive evaluation of ASLR effectiveness across different operating systems and highlights opportunities for Operating System (OS) vendors to strengthen ASLR implementations. Lorenzo Binosi, Gregorio Barzasi, Michele Carminati, Stefano Zanero, Mario Polino |
CCS | 4 |
| 2024 | Tarallo: Evading Behavioral Malware Detectors in the Problem Space
Gabriele Digregorio, Salvatore Maccarrone, Mario D'Onghia, Michele Carminati, Mario Polino, Stefano Zanero |
DIMVA | 7 |
| 2024 | BOTQUAS: Blockchain-based Solutions for Trustworthy Data Sharing in Sustainable and Circular EconomyabstractMonitoring business processes within complex supply chains demands efficient data collection and analytics tailored to diverse phenomena. Traditional centralized solutions face limitations in adapting to the dynamic nature of supply chains. This calls for distributed solutions which break the usual architectural assumption to have a central entity in charge of collecting, integrating and offering tools for the analysis. This project, embedded in a larger initiative called MICS, proposes an inno-vative distributed monitoring solution integrating blockchain for a trustworthy and efficient data analytics strategy that preserves data sovereignty in complex collaborative environments. Leveraging the cloud -edge continuum, the solution aims to ensure secure data exchange, adherence to agreements, and real-time analytics. Expected outcomes include an innovative federated architecture, 5G slice management solutions, an adversarial analysis of supply chain security, and a proof-of-concept implementation of the blockchain-based data flow tracking system. These developments aim to enhance the reliability, security, and efficiency of supply chain monitoring in dynamic industrial environments. Alberto Amico, Vincenzo Apicella, Devis Bianchini, Alberto Butera, Matteo Cesana, Gabriele Digregorio, Massimiliano Garda, Valentina Gatteschi, Corrado Innamorati, Francesco Leotta, Stefano Longari, Maria Rosa Pizzo, Pierluigi Plebani, Noemi Romani, Letizia Tanca, Andrea Vitaletti, Stefano Zanero |
SEAA | 17 |
| 2024 | You Might Have Known It Earlier: Analyzing the Role of Underground Forums in Threat IntelligenceabstractThis paper analyzes 88 million hacker forum posts of a publicly available dataset and 75,000 online articles over a 20-year timespan, studying the potential of hacker forums as a proactive Cyber Threat Intelligence (CTI) source. Using a custom Natural Language Processing pipeline with fine-tuned BERT-based models, we extract named entities from forum posts and reports and cross-reference their date of occurrence over different periods. Our analysis reveals that discussions on hacker forums precede official security reports for over 60% of the identified entities in 20 years of data. This highlights the relevance of these platforms as early indicators of cyber threats. However, our longitudinal analysis shows that such a trend has been constantly decreasing since 2012: forum discussions no longer consistently anticipate threats discussed in cybersecurity reports, possibly due to increased scrutiny or the emergence of alternative channels. This suggests that the CTI community should adapt by identifying and monitoring new platforms where threat actors congregate. Despite not being as thriving as in the first decade of 2000, underground communities are still releasing novel malware and showing interest in discussing malware employed in real cyberattacks. Our results highlight the value of hacker forums as early threat indicators and the importance of proactively monitoring them for potential cyberattack detection. This approach addresses the research gap that predominantly focuses on traditional cybersecurity reports. Tommaso Paladini, Lara Ferro, Mario Polino, Stefano Zanero, Michele Carminati |
RAID | 4 |
| 2024 | Do You Trust Your Device? Open Challenges in IoT Security AnalysisabstractSeveral critical contexts, such as healthcare, smart cities, drones, transportation, and agriculture, nowadays rely on IoT, or more in general embedded, devices that require comprehensive security analysis to ensure their integrity before deployment. Security concerns are often related to vulnerabilities that result from inadequate coding or undocumented features that may create significant privacy issues for users and companies. Current analysis methods, albeit dependent on complex tools, may lead to superficial assessments due to compatibility issues, while authoritative entities struggle with specifying feasible firmware analysis requests for manufacturers within operational contexts. This paper urges the scientific community to collaborate with stakeholders—manufacturers, vendors, security analysts, and experts—to forge a cooperative model that clarifies manufacturer contributions and aligns analysis demands with operational constraints. Aiming at a modular approach, this paper highlights the crucial need to refine security analysis, ensuring more precise requirements, balanced expectations, and stronger partnerships between vendors and analysts. To achieve this, we propose a threat model based on the feasible interactions of actors involved in the security evaluation of a device, with a particular emphasis on the responsibilities and necessities of all entities involved. Lorenzo Binosi, Pietro Mazzini, Alessandro Sanna, Michele Carminati, Giorgio Giacinto, Riccardo Lazzeretti, Stefano Zanero, Mario Polino, Emilio Coppa, Davide Maiorca |
SECRYPT | 7 |
| 2024 | Evaluating the Impact of Privacy-Preserving Federated Learning on CAN Intrusion DetectionabstractThe challenges derived from the data-intensive nature of machine learning in conjunction with technologies that enable novel paradigms such as V2X and the potential offered by 5G communication, allow and justify the deployment of Federated Learning (FL) solutions in the vehicular intrusion detection domain. In this paper, we investigate the effects of integrating FL strategies into the machine learning-based intrusion detection process for on-board vehicular networks. Accordingly, we propose a FL implementation of a state-of-the-art Intrusion Detection System (IDS) for Controller Area Network (CAN), based on LSTM autoencoders. We thoroughly evaluate its detection efficiency and communication overhead, comparing it to a centralized version of the same algorithm, thereby presenting it as a feasible solution. Gabriele Digregorio, Elisabetta Cainazzo, Stefano Longari, Michele Carminati, Stefano Zanero |
VTC Spring | 5 |
| 2023 | DJM-CYBER: A Joint Master in Advanced CybersecurityabstractVarious publicly available studies show that millions of cybersecurity experts are missing worldwide. One possible way to tackle the workforce gap is with tailored higher education programmes. The goal of this paper is to present the relevant projects and frameworks of the European Union which can guide the development of novel cybersecurity education offerings. We describe the most relevant and freely available tools and test them in the development of a joint Master study programme to be offered by a consortium of five European universities. We show that these tools allow educators and study programme developers to map their outputs to the European Cybersecurity Framework developed by the ENISA and other similar frameworks. We complete our work with a detailed analysis of a joint cybersecurity master programme consisting of four innovative and distinctly different tracks. Yianna Danidou, Sara Ricci, Antonio F. Skarmeta, Jiri Hosek, Stefano Zanero, Imre Lendak |
ARES | 5 |
| 2023 | Untangle: Aiding Global Function Pointer Hijacking for Post-CET Binary Exploitation
Alessandro Bertani, Marco Bonelli, Lorenzo Binosi, Michele Carminati, Stefano Zanero, Mario Polino |
DIMVA | 5 |
| 2023 | Rainfuzz: Reinforcement-Learning Driven Heat-Maps for Boosting Coverage-Guided FuzzingabstractFuzzing is a dynamic analysis technique that repeatedly executes the target program with many different inputs to trigger abnormal behavior, such as a crash. One of the most successful techniques consists in generating inputs to increase code-coverage by using a mutational approach: this type of fuzzers maintains a population of inputs, they perform mutations on the inputs in the current population, and they add mutated inputs to the population if they discover new code-coverage in the target program. Researchers are continuously looking for techniques to increment the efficiency of fuzzers; one of these techniques consists in generating heat-maps for targeting specific bytes during the mutation of the input, as not all bytes might be useful for controlling the program's workflow. We propose the first approach in the literature that uses reinforcement learning for building heat-maps, by formalizing the problem of choosing the position to be mutated within the input as a reinforcement-learning problem. We model the policy by means of a neural network, and we train it by using Proximal Policy Optimization (PPO). We implement our approach in Rainfuzz, and we show the effectiveness of its heat-maps by comparing Rainfuzz against an equivalent fuzzer that performs mutations at random positions. We achieve the best performance by running AFL++ and Rainfuzz in parallel (in a collaborative fuzzing setting), outperforming a setting where we run two AFL++ instances in parallel. Lorenzo Binosi, Luca Rullo, Mario Polino, Michele Carminati, Stefano Zanero |
ICPRAM | 5 |
| 2023 | BINO: Automatic recognition of inline binary functions from template classesabstractIn this paper, we propose BINO, a static analysis approach that relieves reverse engineers from the challenging task of recognizing library functions that have been inlined. BINOrecognizes inline calls of methods of C++ template classes (even with unknown data types). We do this through a binary fingerprinting and matching approach. Our fingerprint model captures syntactic and semantic features of an assembly function, along with its Control-Flow Graph structure. Using these fingerprints and subgraph isomorphism, it recognizes inline method calls in a target binary. BINOautomates the fingerprints generation phase by parsing the source code of the template classes and automatically building appropriate binaries with representative inline calls of said methods. We evaluate BINOby performing experiments on a dataset of 555 GitHub C++ projects containing 10600 inline functions, exploring several optimization levels that allow the compiler to inline function calls. We show that our approach can recognize inline function calls to the most used methods of well-known template classes with an F1-Score up to 63% with the -O2, -O3, and -Ofast optimizations levels. Lorenzo Binosi, Mario Polino, Michele Carminati, Stefano Zanero |
Comput. Secur. | 4 |
| 2023 | CANova: A hybrid intrusion detection framework based on automatic signal classification for CANabstractOver the years, vehicles have become increasingly complex and an attractive target for malicious adversaries. This raised the need for effective and efficient Intrusion Detection Systemss (IDSs) for onboard networks able to work with the stringent requirements and the heterogeneity of information transmitted on the Controller Area Network. While state-of-the-art solutions are effective in detecting specific types of anomalies and work on a subset of the CAN signals, no single method can perform better than the others on all types of attacks, particularly if they need to provide predictions to comply with the domain’s real-time constraints. In this paper, we present CANova, a modular framework that exploits the characteristics of the different Controller Area Network (CAN) packets to select the Intrusion Detection Systemss (IDSs) that better fits them. In particular, it uses flow- and payload-based IDSs to analyze the packets’ content and arrival time. We evaluate CANova by comparing its performance against state-of-the-art Intrusion Detection Systemss (IDSs) for in-vehicle network and a comprehensive set of synthetic and real attacks in real-world CAN datasets. We demonstrate that our approach can achieve good performances in terms of detection, false positive rates, and temporal performances. Alessandro Nichelini, Carlo Alberto Pozzoli, Stefano Longari, Michele Carminati, Stefano Zanero |
Comput. Secur. | 5 |
| 2023 | Fraud Detection under Siege: Practical Poisoning Attacks and Defense StrategiesabstractMachine learning (ML) models are vulnerable to adversarial machine learning (AML) attacks. Unlike other contexts, the fraud detection domain is characterized by inherent challenges that make conventional approaches hardly applicable. In this article, we extend the application of AML techniques to the fraud detection task by studying poisoning attacks and their possible countermeasures. First, we present a novel approach for performing poisoning attacks that overcomes the fraud detection domain-specific constraints. It generates fraudulent candidate transactions and tests them against a machine learning-based Oracle , which simulates the target fraud detection system aiming at evading it. Misclassified fraudulent candidate transactions are then integrated into the target detection system’s training set, poisoning its model and shifting its decision boundary. Second, we propose a novel approach that extends the adversarial training technique to mitigate AML attacks: During the training phase of the detection system, we generate artificial frauds by modifying random original legitimate transactions; then, we include them in the training set with the correct label. By doing so, we instruct our model to recognize evasive transactions before an attack occurs. Using two real bank datasets, we evaluate the security of several state-of-the-art fraud detection systems by deploying our poisoning attack with different degrees of attacker’s knowledge and attacking strategies. The experimental results show that our attack works even when the attacker has minimal knowledge of the target system. Then, we demonstrate that the proposed countermeasure can mitigate adversarial attacks by reducing the stolen amount of money up to 100%. Tommaso Paladini, Francesco Monti, Mario Polino, Michele Carminati, Stefano Zanero |
ACM Trans. Priv. Secur. | 5 |
| 2022 | CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksabstractCurrent research in the automotive domain has proven the limitations of the Controller Area Network (CAN) protocol from a security standpoint. Application-layer attacks, which involve the creation of malicious packets, are deemed feasible from remote but can be easily detected by modern Intrusion Detection Systems (IDSs). On the other hand, more recent link-layer attacks are stealthier and possibly more disruptive but require physical access to the bus. In this paper, we present CANflict, a software-only approach that allows reliable manipulation of the CAN bus at the data link layer from an unmodified microcontroller, overcoming the limitations of state-of-the-art works. We demonstrate that it is possible to deploy stealthy CAN link-layer attacks from a remotely compromised ECU, targeting another ECU on the same CAN network. To do this, we exploit the presence of pin conflicts between microcontroller peripherals to craft polyglot frames, which allows an attacker to control the CAN traffic at the bit level and bypass the protocol's rules. We experimentally demonstrate the effectiveness of our approach on high-, mid-, and low-end microcontrollers, and we provide the ground for future research by releasing an extensible tool that can be used to implement our approach on different platforms and to build CAN countermeasures at the data link layer. Alvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino, Stefano Zanero |
CCS | 5 |
| 2022 | Apícula: Static detection of API calls in generic streams of bytes
Mario D'Onghia, Matteo Salvadore, Benedetto Maria Nespoli, Michele Carminati, Mario Polino, Stefano Zanero |
Comput. Secur. | 6 |
| 2022 | A Systematical and longitudinal study of evasive behaviors in windows malware
Nicola Galloro, Mario Polino, Michele Carminati, Andrea Continella, Stefano Zanero |
Comput. Secur. | 5 |
| 2022 | GOLIATH: A Decentralized Framework for Data Collection in Intelligent Transportation SystemsabstractIntelligent Transportation Systems (ITSs) technology has advanced during the past years, and it is now used for several applications that require vehicles to exchange real-time data, such as in traffic information management. Traditionally, road traffic information has been collected using on-site sensors. However, crowd-sourcing traffic information from onboard sensors or smartphones has become a viable alternative. State-of-the-art solutions currently follow a centralized model where only the service provider has complete access to the collected traffic data and represent a single point of failure and trust. In this paper, we proposeGOLIATH, a blockchain-based decentralized framework that runs on the In-Vehicle Infotainment (IVI) system to collect real-time information exchanged between the network’s participants. Our approach mitigates the limitations of existing crowd-sourcing centralized solutions by guaranteeing trusted information collection and exchange, fully exploiting the intrinsic distributed nature of vehicles. We demonstrate its feasibility in the context of vehicle positioning and traffic information management. Each vehicle participating in the decentralized network shares its position and neighbors’ ones in the form of a transaction recorded on the ledger, which uses a novel consensus mechanism to validate it. We design the consensus mechanism resilient against a realistic set of adversaries that aim to tamper or disable the communication. We evaluate the proposed framework in a simulated (but realistic) environment, which considers different threats and allows showing its robustness and safety properties. Davide Maffiola, Stefano Longari, Michele Carminati, Mara Tanelli, Stefano Zanero |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2021 | SyML: Guiding Symbolic Execution Toward Vulnerable States Through Pattern LearningabstractExploring many execution paths in a binary program is essential to discover new vulnerabilities. Dynamic Symbolic Execution (DSE) is useful to trigger complex input conditions and enables an accurate exploration of a program while providing extensive crash replayability and semantic insights. Nicola Ruaro, Kyle Zeng, Lukas Dresel, Mario Polino, Tiffany Bao, Andrea Continella, Stefano Zanero, Christopher Krügel, Giovanni Vigna |
RAID | 7 |
| 2021 | CANnolo: An Anomaly Detection System Based on LSTM Autoencoders for Controller Area NetworkabstractAutomotive security has gained significant traction in the last decade thanks to the development of new connectivity features that have brought the vehicle from an isolated environment to an externally facing domain. Researchers have shown that modern vehicles are vulnerable to multiple types of attacks leveraging remote, direct and indirect physical access, which allow attackers to gain control and affect safety-critical systems. Conversely, Intrusion Detection Systems (IDSs) have been proposed by both industry and academia to identify attacks and anomalous behaviours. In this article, we propose CANnolo, an IDS based on Long Short-Term Memory (LSTM)-autoencoders to identify anomalies in Controller Area Networks (CANs). During a training phase, CANnolo automatically analyzes the CAN streams and builds a model of the legitimate data sequences. Then, it detects anomalies by computing the difference between the reconstructed and the respective real sequences. We experimentally evaluated CANnolo on a set of simulated attacks applied over a real-world dataset. We show that our approach outperforms the state-of-the-art model by improving the detection rate and precision. Stefano Longari, Daniel Humberto Nova Valcarcel, Mattia Zago, Michele Carminati, Stefano Zanero |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2020 | Constrained Concealment Attacks against Reconstruction-based Anomaly Detectors in Industrial Control SystemsabstractRecently, reconstruction-based anomaly detection was proposed as an effective technique to detect attacks in dynamic industrial control networks. Unlike classical network anomaly detectors that observe the network traffic, reconstruction-based detectors operate on the measured sensor data, leveraging physical process models learned a priori. Alessandro Erba 0001, Riccardo Taormina, Stefano Galelli, Marcello Pogliani, Michele Carminati, Stefano Zanero, Nils Ole Tippenhauer |
ACSAC | 6 |
| 2020 | NoSQL Breakdown: A Large-scale Analysis of Misconfigured NoSQL ServicesabstractIn the last years, NoSQL databases have grown in popularity due to their easy-to-deploy, reliable, and scalable storage mechanism. While most NoSQL services offer access control mechanisms, their default configurations grant access without any form of authentication, resulting in misconfigurations that may expose data to the Internet, as demonstrated by the recent high-profile data leaks. Dario Ferrari, Michele Carminati, Mario Polino, Stefano Zanero |
ACSAC | 4 |
| 2020 | Detecting Insecure Code Patterns in Industrial Robot ProgramsabstractIndustrial robots are complex and customizable machines that can be programmed with proprietary domain-specific languages. These languages provide not only movement instructions, but also access to low-level system resources such as the network or the file system. Although useful, these features can lead to taint-style vulnerabilities and can be misused to implement malware---on par with general-purpose programming languages. Marcello Pogliani, Federico Maggi 0001, Marco Balduzzi, Davide Quarta, Stefano Zanero |
AsiaCCS | 5 |
| 2020 | Evasion Attacks against Banking Fraud Detection Systems
Michele Carminati, Luca Santini, Mario Polino, Stefano Zanero |
RAID | 4 |
| 2018 | There's a Hole in that Bucket!: A Large-scale Analysis of Misconfigured S3 BucketsabstractCloud storage services are an efficient solution for a variety of use cases, allowing even non-skilled users to benefit from fast, reliable and easy-to-use storage. However, using public cloud services for storage comes with security and privacy concerns. In fact, managing access control at scale is often particularly hard, as the size and complexity rapidly increases, especially when the role of access policies is underestimated, resulting in dangerous misconfigurations. Andrea Continella, Mario Polino, Marcello Pogliani, Stefano Zanero |
ACSAC | 4 |
| 2018 | FraudBuster: Temporal Analysis and Detection of Advanced Financial Frauds
Michele Carminati, Alessandro Baggio, Federico Maggi 0001, Umberto Spagnolini, Stefano Zanero |
DIMVA | 5 |
| 2018 | ELISA: ELiciting ISA of Raw Binaries for Fine-Grained Code and Data Separation
Pietro De Nicolao, Marcello Pogliani, Mario Polino, Michele Carminati, Davide Quarta, Stefano Zanero |
DIMVA | 6 |
| 2018 | Extended Abstract: Toward Systematically Exploring Antivirus Engines
Davide Quarta, Federico Salvioni, Andrea Continella, Stefano Zanero |
DIMVA | 4 |
| 2018 | Security Evaluation of a Banking Fraud Analysis SystemabstractThe significant growth of banking fraud, fueled by the underground economy of malware, has raised the need for effective detection systems. Therefore, in the last few years, banks have upgraded their security to protect transactions from fraud. State-of-the-art solutions detect fraud as deviations from customers’ spending habits. To the best of our knowledge, almost all existing approaches do not provide an in-depth model’s granularity and security analysis against elusive attacks. In this article, we examine Banksealer, a decision support system for banking fraud analysis that evaluates the influence on detection performance of the granularity at which spending habits are modeled and its security against evasive attacks. First, we compare user-centric modeling, which builds a model for each user, with system-centric modeling, which builds a model for the entire system, from the point of view of detection performance. Then, we assess the robustness of Banksealer against malicious attackers that are aware of the structure of the models in use. To this end, we design and implement a proof-of-concept attack tool that performs mimicry attacks, emulating a sophisticated attacker that cloaks frauds to avoid detection. We experimentally confirm the feasibility of such attacks, their cost, and the effort required by an attacker in order to perform them. In addition, we discuss possible countermeasures. We provide a comprehensive evaluation on a large real-world dataset obtained from one of the largest Italian banks. Michele Carminati, Mario Polino, Andrea Continella, Andrea Lanzi, Federico Maggi 0001, Stefano Zanero |
ACM Trans. Priv. Secur. | 6 |
| 2017 | A Stealth, Selective, Link-Layer Denial-of-Service Attack Against Automotive Networks
Andrea Palanca, Eric Evenchick, Federico Maggi 0001, Stefano Zanero |
DIMVA | 4 |
| 2017 | Measuring and Defeating Anti-Instrumentation-Equipped Malware
Mario Polino, Andrea Continella, Sebastiano Mariani, Stefano D'Alessio, Lorenzo Fontana, Fabio Gritti, Stefano Zanero |
DIMVA | 7 |
| 2017 | An Experimental Security Analysis of an Industrial Robot ControllerabstractIndustrial robots, automated manufacturing, and efficient logistics processes are at the heart of the upcoming fourth industrial revolution. While there are seminal studies on the vulnerabilities of cyber-physical systems in the industry, as of today there has been no systematic analysis of the security of industrial robot controllers. We examine the standard architecture of an industrial robot and analyze a concrete deployment from a systems security standpoint. Then, we propose an attacker model and confront it with the minimal set of requirements that industrial robots should honor: precision in sensing the environment, correctness in execution of control logic, and safety for human operators. Following an experimental and practical approach, we then show how our modeled attacker can subvert such requirements through the exploitation of software vulnerabilities, leading to severe consequences that are unique to the robotics domain. We conclude by discussing safety standards and security challenges in industrial robotics. Davide Quarta, Marcello Pogliani, Mario Polino, Federico Maggi 0001, Andrea Maria Zanchettin, Stefano Zanero |
IEEE Symposium on Security and Privacy | 6 |
| 2017 | Prometheus: Analyzing WebInject-based information stealersabstractNowadays Information stealers are reaching high levels of sophistication. The number of families and variants observed increased exponentially in the last years. Furthermore, these trojans are sold on underground markets along with automatic frameworks that include web-based administration panels, builders and customization procedures. From a technical point of view such malware is equipped with a functionality, called WebInject, that exploits API hooking techniques to intercept all sensitive data in a browser context and modify web pages on infected hosts. In this paper we propose Prometheus, an automatic system that is able to analyze trojans that base their attack technique on DOM modifications. Prometheus is able to identify the injection operations performed by malware, and generate signatures based on the injection behavior. Furthermore, it is able to extract the WebInject targets by using memory forensic techniques. We evaluated Prometheus against real-world, online websites and a dataset of distinct variants of financial trojans. In our experiments we show that our approach correctly recognizes known variants of WebInject-based malware and successfully extracts the WebInject targets. Andrea Continella, Michele Carminati, Mario Polino, Andrea Lanzi, Stefano Zanero, Federico Maggi 0001 |
J. Comput. Secur. | 5 |
| 2016 | ShieldFS: a self-healing, ransomware-aware filesystem
Andrea Continella, Alessandro Guagnelli, Giovanni Zingaro, Giulio De Pasquale, Alessandro Barenghi, Stefano Zanero, Federico Maggi 0001 |
ACSAC | 6 |
| 2016 | Trellis: Privilege Separation for Multi-user Applications Made Easy
Andrea Mambretti, Kaan Onarlioglu, Collin Mulliner, William K. Robertson, Engin Kirda, Federico Maggi 0001, Stefano Zanero |
RAID | 7 |
| 2016 | XSS PEEKER: Dissecting the XSS Exploitation Techniques and Fuzzing Mechanisms of Blackbox Web Application Scanners
Enrico Bazzoli, Claudio Criscione, Federico Maggi 0001, Stefano Zanero |
SEC | 4 |
| 2016 | GreatEatlon: Fast, Static Detection of Mobile Ransomware
Nicola Dellarocca, Niccolò Andronio, Stefano Zanero, Federico Maggi 0001 |
SecureComm | 4 |
| 2015 | Grab 'n Run: Secure and Practical Dynamic Code Loading for Android ApplicationsabstractAndroid introduced the dynamic code loading (DCL) mechanism to allow for code reuse, to achieve extensibility, to enable updating functionalities, or to boost application start-up performance. In spite of its wide adoption by developers, previous research has shown that the secure implementation of DCL-based functionality is challenging, often leading to remote code injection vulnerabilities. Unfortunately, previous attempts to address this problem by both the academic and Android developers communities are affected by either practicality or completeness issues, and, in some cases, are affected by severe vulnerabilities. Luca Falsina, Yanick Fratantonio, Stefano Zanero, Christopher Krügel, Giovanni Vigna, Federico Maggi 0001 |
ACSAC | 3 |
| 2015 | Practical Exploit Generation for Intent Message Vulnerabilities in AndroidabstractAndroid's Inter-Component Communication (ICC) mechanism strongly relies on Intent messages. Unfortunately, due to the lack of message origin verification in Intents, application security completely relies on the programmer's skill and attention. In this paper, we advance the state of the art by developing a method to automatically detect potential vulnerabilities and, most importantly, demonstrate whether they can be exploited or not. To this end, we adopt a formal approach to automatically produce malicious payloads that can trigger dangerous behavior in vulnerable applications. We test our methods on a representative sample of applications, and we find that 29 out of 64 tested applications are potentially vulnerable, while 26 of them are automatically proven to be exploitable. Daniele Gallingani, Rigel Gjomemo, V. N. Venkatakrishnan, Stefano Zanero |
CODASPY | 4 |
| 2015 | Jackdaw: Towards Automatic Reverse Engineering of Large Datasets of Binaries
Mario Polino, Andrea Scorti, Federico Maggi 0001, Stefano Zanero |
DIMVA | 4 |
| 2015 | HelDroid: Dissecting and Detecting Mobile Ransomware
Niccolò Andronio, Stefano Zanero, Federico Maggi 0001 |
RAID | 2 |
| 2015 | BankSealer: A decision support system for online banking fraud analysis and investigation
Michele Carminati, Roberto Caron, Federico Maggi 0001, Ilenia Epifani, Stefano Zanero |
Comput. Secur. | 5 |
| 2014 | Faces in the Distorting Mirror: Revisiting Photo-based Social AuthenticationabstractIn an effort to hinder attackers from compromising user accounts, Facebook launched a form of two-factor authentication called social authentication (SA), where users are required to identify photos of their friends to complete a log-in attempt. Recent research, however, demonstrated that attackers can bypass the mechanism by employing face recognition software. Here we demonstrate an alternative attack. that employs image comparison techniques to identify the SA photos within an offline collection of the users' photos. Iasonas Polakis, Panagiotis Ilia, Federico Maggi 0001, Marco Lancini, Georgios Kontaxis, Stefano Zanero, Sotiris Ioannidis, Angelos D. Keromytis |
CCS | 6 |
| 2014 | AndRadar: Fast Discovery of Android Applications in Alternative Markets
Martina Lindorfer, Stamatis Volanis, Alessandro Sisto 0001, Matthias Neugschwandtner, Elias Athanasopoulos, Federico Maggi 0001, Christian Platzer, Stefano Zanero, Sotiris Ioannidis |
DIMVA | 8 |
| 2014 | Phoenix: DGA-Based Botnet Tracking and Intelligence
Stefano Schiavoni, Federico Maggi 0001, Lorenzo Cavallaro, Stefano Zanero |
DIMVA | 4 |
| 2014 | ZARATHUSTRA: Extracting Webinject signatures from banking trojansabstractModern trojans are equipped with a functionality, called WebInject, that can be used to silently modify a web page on the infected end host. Given its flexibility, WebInject-based malware is becoming a popular information-stealing mechanism. In addition, the structured and well-organized malware-as-a-service model makes revenue out of customization kits, which in turns leads to high volumes of binary variants. Analysis approaches based on memory carving to extract the decrypted webinject.txt and config.bin files at runtime make the strong assumption that the malware will never change the way such files are handled internally, and therefore are not future proof by design. In addition, developers of sensitive web applications (e.g., online banking) have no tools that they can possibly use to even mitigate the effect of WebInjects. Claudio Criscione, Fabio Bosatelli, Stefano Zanero, Federico Maggi 0001 |
PST | 3 |
| 2014 | BankSealer: An Online Banking Fraud Analysis and Decision Support System
Michele Carminati, Roberto Caron, Federico Maggi 0001, Ilenia Epifani, Stefano Zanero |
SEC | 5 |
| 2014 | Stranger danger: exploring the ecosystem of ad-based URL shortening servicesabstractURL shortening services facilitate the need of exchanging long URLs using limited space, by creating compact URL aliases that redirect users to the original URLs when followed. Some of these services show advertisements (ads) to link-clicking users and pay a commission of their advertising earnings to link-shortening users. Nick Nikiforakis, Federico Maggi 0001, Gianluca Stringhini, M. Zubair Rafique, Wouter Joosen, Christopher Krügel, Frank Piessens, Giovanni Vigna, Stefano Zanero |
WWW | 9 |
| 2013 | A comprehensive black-box methodology for testing the forensic characteristics of solid-state drivesabstractSolid-state drives (SSDs) are inherently different from traditional drives, as they incorporate data-optimization mechanisms to overcome their limitations (such as a limited number of program-erase cycles, or the need of blanking a block before writing). The most common optimizations are wear leveling, trimming, compression, and garbage collection, which operate transparently to the host OS and, in certain cases, even when the disks are disconnected from a computer (but still powered up). In simple words, SSD controllers are designed to hide these internals completely, rendering them inaccessible if not through direct acquisition of the memory cells. Gabriele Bonetti, Marco Viglione, Alessandro Frossi, Federico Maggi 0001, Stefano Zanero |
ACSAC | 5 |
| 2013 | Two years of short URLs internet measurement: security threats and countermeasuresabstractURL shortening services have become extremely popular. However, it is still unclear whether they are an effective and reliable tool that can be leveraged to hide malicious URLs, and to what extent these abuses can impact the end users. With these questions in mind, we first analyzed existing countermeasures adopted by popular shortening services. Surprisingly, we found such countermeasures to be ineffective and trivial to bypass. This first measurement motivated us to proceed further with a large-scale collection of the HTTP interactions that originate when web users access live pages that contain short URLs. To this end, we monitored 622 distinct URL shortening services between March 2010 and April 2012, and collected 24,953,881 distinct short URLs. With this large dataset, we studied the abuse of short URLs. Despite short URLs are a significant, new security risk, in accordance with the reports resulting from the observation of the overall phishing and spamming activity, we found that only a relatively small fraction of users ever encountered malicious short URLs. Interestingly, during the second year of measurement, we noticed an increased percentage of short URLs being abused for drive-by download campaigns and a decreased percentage of short URLs being abused for spam campaigns. In addition to these security-related findings, our unique monitoring infrastructure and large dataset allowed us to complement previous research on short URLs and analyze these web services from the user's perspective. Federico Maggi 0001, Alessandro Frossi, Stefano Zanero, Gianluca Stringhini, Brett Stone-Gross, Christopher Krügel, Giovanni Vigna |
WWW | 3 |
| 2012 | Lines of malicious code: insights into the malicious software industryabstractMalicious software installed on infected computers is a fundamental component of online crime. Malware development thus plays an essential role in the underground economy of cyber-crime. Malware authors regularly update their software to defeat defenses or to support new or improved criminal business models. A large body of research has focused on detecting malware, defending against it and identifying its functionality. In addition to these goals, however, the analysis of malware can provide a glimpse into the software development industry that develops malicious code. Martina Lindorfer, Alessandro Di Federico, Federico Maggi 0001, Paolo Milani Comparetti, Stefano Zanero |
ACSAC | 5 |
| 2012 | All your face are belong to us: breaking Facebook's social authenticationabstractTwo-factor authentication is widely used by high-value services to prevent adversaries from compromising accounts using stolen credentials. Facebook has recently released a two-factor authentication mechanism, referred to as Social Authentication, which requires users to identify some of their friends in randomly selected photos. A recent study has provided a formal analysis of social authentication weaknesses against attackers inside the victim's social circles. In this paper, we extend the threat model and study the attack surface of social authentication in practice, and show how any attacker can obtain the information needed to solve the challenges presented by Facebook. We implement a proof-of-concept system that utilizes widely available face recognition software and cloud services, and evaluate it using real public data collected from Facebook. Under the assumptions of Facebook's threat model, our results show that an attacker can obtain access to (sensitive) information for at least 42% of a user's friends that Facebook uses to generate social authentication challenges. By relying solely on publicly accessible information, a casual attacker can solve 22% of the social authentication tests in an automated fashion, and gain a significant advantage for an additional 56% of the tests, as opposed to just guessing. Additionally, we simulate the scenario of a determined attacker placing himself inside the victim's social circle by employing dummy accounts. In this case, the accuracy of our attack greatly increases and reaches 100% when 120 faces per friend are accessible by the attacker, even though it is very accurate with as little as 10 faces. Iasonas Polakis, Marco Lancini, Georgios Kontaxis, Federico Maggi 0001, Sotiris Ioannidis, Angelos D. Keromytis, Stefano Zanero |
ACSAC | 7 |
| 2012 | Context-Based File Block Classification
Luigi Sportiello, Stefano Zanero |
IFIP Int. Conf. Digital Forensics | 2 |
| 2012 | Integrated detection of anomalous behavior of computer infrastructuresabstractOur research concentrates on anomaly detection techniques, which have both industrial applications such as network monitoring and protection, as well as research applications such as software behavioral analysis or malware classification. During our doctoral research, we worked on anomaly detection from three different perspective, as a complex computer infrastructure has several weak spots that must be protected. We first focused on the operating system, central to any computer, to avoid malicious code to subvert its normal activity. Secondly, we concentrated on web applications, which are the main interface to modern computing: Because of their immense popularity, they have indeed become the most targeted entry point of intrusions. Last, we developed novel techniques with the aim of identifying related events (e.g., alerts reported by intrusion detection systems) to build new and more compact knowledge to detect malicious activity on large-scale systems. During our research we enhanced existing anomaly detection tools and also contributed with new ones. Such tools have been tested over different datasets, both synthetic data and real network traffic, and lead to interesting results that were accepted for publication at main security venues. Federico Maggi 0001, Stefano Zanero |
NOMS | 2 |
| 2011 | File Block Classification by Support Vector MachineabstractRetrieval of files without the support of file system structures is arguably essential for digital forensics. Files are typically stored as sequences of data blocks, which have to be reconstructed in the retrieval process. This is commonly performed, among other approaches, through file carving, in general detecting the original block sequences by means of signatures of known headers and footers of files. Of course, this creates challenges with fragmented files, where blocks belonging to different files may be interleaved. Ways to classify file blocks into file types relying on their content may provide a support to achieve a successful reconstruction. We propose to classify file blocks using Support Vector Machines (SVMs), and we do so by studying in-depth the impact of an appropriate selection of the features used in the classification process. We analyze several potential features and test their performance over a large and representative collection of file blocks and file types. We find out that SVM classifiers can achieve a good accuracy and that a specific type of features (based on byte frequency distribution) performs well across almost all of the examined file types. Luigi Sportiello, Stefano Zanero |
ARES | 2 |
| 2011 | Poster: fast, automatic iPhone shoulder surfing
Stefano Maggi, Alberto Volpatto, Simone Gasparini, Giacomo Boracchi, Stefano Zanero |
CCS | 5 |
| 2011 | BURN: baring unknown rogue networksabstractManual analysis of security-related events is still a necessity to investigate non-trivial cyber attacks. This task is particularly hard when the events involve slow, stealthy and large-scale activities typical of the modern cybercriminals' strategy. In this regard, visualization tools can effectively help analysts in their investigations. In this paper, we present BURN, an interactive visualization tool for displaying autonomous systems exhibiting rogue activity that helps at finding misbehaving networks through visual and interactive exploration. Up to seven values are displayed in a single visual element, while avoiding cumbersome and confusing maps. To this end, animations and alpha channels are leveraged to create simple views that highlight relevant activity patterns. In addition, BURN incorporates a simple algorithm to identify migrations of nefarious services across autonomous systems, which can support, for instance, root-cause analysis and law enforcement investigations. Francesco Roveta, Giorgio Caviglia, Luca Di Mario, Stefano Zanero, Federico Maggi 0001, Paolo Ciuccarelli |
VizSEC | 4 |
| 2010 | Identifying Dormant Functionality in Malware ProgramsabstractTo handle the growing flood of malware, security vendors and analysts rely on tools that automatically identify and analyze malicious code. Current systems for automated malware analysis typically follow a dynamic approach, executing an unknown program in a controlled environment (sandbox) and recording its runtime behavior. Since dynamic analysis platforms directly run malicious code, they are resilient to popular malware defense techniques such as packing and code obfuscation. Unfortunately, in many cases, only a small subset of all possible malicious behaviors is observed within the short time frame that a malware sample is executed. To mitigate this issue, previous work introduced techniques such as multipath or forced execution to increase the coverage of dynamic malware analysis. Unfortunately, using these techniques is potentially expensive, as the number of paths that require analysis can grow exponentially. In this paper, we propose REANIMATOR, a novel solution to determine the capabilities (malicious functionality) of malware programs. Our solution is based on the insight that we can leverage behavior observed while dynamically executing a specific malware sample to identify similar functionality in other programs. More precisely, when we observe malicious actions during dynamic analysis, we automatically extract and model the parts of the malware binary that are responsible for this behavior. We then leverage these models to check whether similar code is present in other samples. This allows us to statically identify dormant functionality (functionality that is not observed during dynamic analysis) in malicious programs. We evaluate our approach on thousands of realworld malware samples, and we show that our system is successful in identifying additional, malicious functionality. As a result, our approach can significantly improve the coverage of malware analysis results. Paolo Milani Comparetti, Guido Salvaneschi, Engin Kirda, Clemens Kolbitsch, Christopher Krügel, Stefano Zanero |
IEEE Symposium on Security and Privacy | 6 |
| 2010 | Detecting Intrusions through System Call Sequence and Argument AnalysisabstractWe describe an unsupervised host-based intrusion detection system based on system call arguments and sequences. We define a set of anomaly detection models for the individual parameters of the call. We then describe a clustering process that helps to better fit models to system call arguments and creates interrelations among different arguments of a system call. Finally, we add a behavioral Markov model in order to capture time correlations and abnormal behaviors. The whole system needs no prior knowledge input; it has a good signal-to-noise ratio, and it is also able to correctly contextualize alarms, giving the user more information to understand whether a true or false positive happened, and to detect global variations over the entire execution flow, as opposed to punctual ones over individual instances. Federico Maggi 0001, Matteo Matteucci, Stefano Zanero |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2009 | Selecting and Improving System Call Models for Anomaly Detection
Alessandro Frossi, Federico Maggi 0001, Gian Luigi Rizzo, Stefano Zanero |
DIMVA | 4 |
| 2009 | BlueBat: Towards Practical Bluetooth HoneypotsabstractIt is still difficult to assess the real danger posed by Bluetooth-propagated malware. BlueBat is an effort to build and deploy a practical honeypot for capturing in-the-wild samples and empirically study malware prevalence. This paper describes the design and implementation of a first prototype, focusing on Bluetooth worms propagating over the OBEX Push service. We develop and perform initial field testing of different types of sensors, in order to achieve an optimal collection capability. We analyze the results of the field tests, and demonstrate various design constraints. Also, from these preliminary tests, we cast some doubts on the prevalence of in-the-wild Bluetooth worms, and hint at some reasons why such threat could be more limited than previously thought. Antonio Galante, Ary Kokos, Stefano Zanero |
ICC | 3 |
| 2008 | Unsupervised learning algorithms for intrusion detectionabstractThis work summarizes our research on the topic of the application of unsupervised learning algorithms to the problem of intrusion detection, and in particular our main research results in network intrusion detection. We proposed a novel, two tier architecture for network intrusion detection, capable of clustering packet payloads and correlating anomalies in the packet stream. We show the experiments we conducted on such architecture, we give performance results, and we compare our achievements with other comparable existing systems. Stefano Zanero, Giuseppe Serazzi |
NOMS | 1 |
| 2007 | On the Use of Different Statistical Tests for Alert Correlation - Short Paper
Federico Maggi 0001, Stefano Zanero |
RAID | 2 |
| 2004 | Lessons learned from the Italian law on privacy - Part I
Pierluigi Perri, Stefano Zanero |
Comput. Law Secur. Rev. | 2 |
| 2004 | Lessons learned from the Italian law on privacy - Part II
Pierluigi Perri, Stefano Zanero |
Comput. Law Secur. Rev. | 2 |