Giovanni Lagorio

dblp:00/5916 · DBLP profile ↗
← Back
18ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0002-6632-1523ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 12 · 2 first-author · 1 since 2021Security and privacy · 3 · 2 since 2021Theory of computation · 3 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2023 Fight silent horror unit test methods by consulting a TestWizard
abstract
Abstract Tests, when not correctly implemented, can pass on incorrect system implementations rather than fail. In this case, they are named silent horrors or false‐negative tests. They make releasing low‐quality (buggy) versions of the software system more probable. Furthermore, faithfully implementing test specifications is crucial when they play the role of documentation, like when documenting components or services or driving legacy systems' re‐engineering. This paper presents TestWizard, a novel approach and tool for automatically assessing individual tests' quality from the point of view of their coherence to specifications. TestWizard automatically assesses the quality of each individual test case w.r.t. its specification, providing detailed reports on why a single test is a false negative, hence helping testers fix them. Thus, TestWizard can help to automate the test code review process, which is still mainly manual today. The analysis of 1012 test implementations, developed by 123 students in three experiments, shows that TestWizard is (1) by far more accurate than code review performed by multiple students, (2) slightly better than code review performed by three senior experts, and (3) always able to detect a significant percentage of false‐negative test methods (up to 21.22%).
Maura Cerioli, Giovanni Lagorio, Maurizio Leotta, Filippo Ricca
J. Softw. Evol. Process.2
2021 Functionality-Preserving Black-Box Optimization of Adversarial Windows Malware
abstract
Windows malware detectors based on machine learning are vulnerable to adversarial examples, even if the attacker is only given black-box query access to the model. The main drawback of these attacks is that: ( i) they are query-inefficient, as they rely on iteratively applying random transformations to the input malware; and ( ii) they may also require executing the adversarial malware in a sandbox at each iteration of the optimization process, to ensure that its intrusive functionality is preserved. In this paper, we overcome these issues by presenting a novel family of black-box attacks that are both query-efficient and functionality-preserving, as they rely on the injection of benign content (which will never be executed) either at the end of the malicious file, or within some newly-created sections. Our attacks are formalized as a constrained minimization problem which also enables optimizing the trade-off between the probability of evading detection and the size of the injected payload. We empirically investigate this trade-off on two popular static Windows malware detectors, and show that our black-box attacks can bypass them with only few queries and small payloads, even when they only return the predicted labels. We also evaluate whether our attacks transfer to other commercial antivirus solutions, and surprisingly find that they can evade, on average, more than 12 commercial antivirus engines. We conclude by discussing the limitations of our approach, and its possible future extensions to target malware classifiers based on dynamic analysis.
Luca Demetrio, Battista Biggio, Giovanni Lagorio, Fabio Roli, Alessandro Armando
IEEE Trans. Inf. Forensics Secur.3
2021 Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection
abstract
Recent work has shown that adversarial Windows malware samples—referred to as adversarial EXE mples in this article—can bypass machine learning-based detection relying on static code analysis by perturbing relatively few input bytes. To preserve malicious functionality, previous attacks either add bytes to existing non-functional areas of the file, potentially limiting their effectiveness, or require running computationally demanding validation steps to discard malware variants that do not correctly execute in sandbox environments. In this work, we overcome these limitations by developing a unifying framework that does not only encompass and generalize previous attacks against machine-learning models, but also includes three novel attacks based on practical, functionality-preserving manipulations to the Windows Portable Executable file format. These attacks, named Full DOS , Extend , and Shift , inject the adversarial payload by respectively manipulating the DOS header, extending it, and shifting the content of the first section. Our experimental results show that these attacks outperform existing ones in both white-box and black-box scenarios, achieving a better tradeoff in terms of evasion rate and size of the injected payload, while also enabling evasion of models that have been shown to be robust to previous attacks. To facilitate reproducibility of our findings, we open source our framework and all the corresponding attack implementations as part of the secml-malware Python library. We conclude this work by discussing the limitations of current machine learning-based malware detectors, along with potential mitigation strategies based on embedding domain knowledge coming from subject-matter experts directly into the learning process.
Luca Demetrio, Scott E. Coull, Battista Biggio, Giovanni Lagorio, Alessandro Armando, Fabio Roli
ACM Trans. Priv. Secur.4
2019 ZenHackAdemy: Ethical Hacking @ DIBRIS
abstract
Cybersecurity attacks are on the rise, and the current response is not effective enough. The need for a competent workforce, able to face attackers, is increasing. At the moment, the gap between academia and real-world skills is huge and academia cannot provide students with skills that match those of an attacker. To pass on these skills, teachers have to train students in scenarios as close as possible to real-world ones. Capture the Flag (CTF) competitions are a great tool to achieve this goal, since they encourage students to think as an attacker does, thus creating more awareness on the modalities and consequences of an attack. We describe our experience in running an educational activity on ethical hacking, which we proposed to computer science and computer engineering students. We organized seminars, outside formal classes, and provided online support on the hands-on part of the training. We delivered different types of exercises and held a final CTF competition. These activities resulted in growing a community of students and researchers interested in cybersecurity, and some of them have formed ZenHack, an official CTF team.
Luca Demetrio, Giovanni Lagorio, Marina Ribaudo, Enrico Russo 0001, Andrea Valenza
CSEDU (1)2
2017 RmPerm: A Tool for Android Permissions Removal
abstract
Android apps are generally over-privileged, i.e., they request more permissions than they actually need to execute properly. Prior to version 6 users can install an app only by accepting all its requested permissions, while newer Android versions allow users to dynamically grant/deny groups of permissions. Since some them impact on users' privacy, we argue that users should be granted control at the granularity of the single permission. We propose a novel approach, which does not require any change to the underlying OS, allowing users to selectively remove permissions from apps before installing them, and with a finer granularity. \nWe developed \tool, an open-source tool, that implements our methodology, and we present the viability of our approach via an empirical assessment on 81K apps, \nunderlining that, in the worst case, up to 86% of the apps can execute without crashing when none of the requested privacy-related permissions are granted.
Simone Aonzo, Giovanni Lagorio, Alessio Merlo
SECRYPT2
2012 Featherweight Jigsaw - Replacing inheritance by composition in Java-like languages
Giovanni Lagorio, Marco Servetto, Elena Zucca
Inf. Comput.1
2010 Complete coinductive subtyping for abstract compilation of object-oriented languages
abstract
Coinductive abstract compilation is a novel technique, which has been recently introduced, for defining precise type systems for object-oriented languages. In this approach, type inference consists in translating the program to be analyzed into a Horn formula f, and in resolving a certain goal w.r.t. the coinductive (that is, the greatest) Herbrand model of f.
Davide Ancona, Giovanni Lagorio
FTfJP@ECOOP2
2010 Strong exception-safety for Java-like languages
abstract
"Exception-safety strong guarantee: The operation has either completed successfully or thrown an exception, leaving the program state exactly as it was before the operation started." David Abrahams [1] The above definition of strong exception-safety comes from the world of C++, but it can be applied to any language.
Giovanni Lagorio, Marco Servetto
FTfJP@ECOOP1
2009 Coinductive Type Systems for Object-Oriented Languages
Davide Ancona, Giovanni Lagorio
ECOOP2
2009 Featherweight Jigsaw: A Minimal Core Calculus for Modular Composition of Classes
Giovanni Lagorio, Marco Servetto, Elena Zucca
ECOOP1
2008 Gesper: Support to Capitalize on Experience in a Network of SMEs
Maura Cerioli, Giovanni Lagorio, Enrico Morten, Gianna Reggio
ISoLA2
2006 A flexible model for dynamic linking in Java and C#
Sophia Drossopoulou, Giovanni Lagorio, Susan Eisenbach
Theor. Comput. Sci.2
2003 Flexible Models for Dynamic Linking
Sophia Drossopoulou, Giovanni Lagorio, Susan Eisenbach
ESOP2
2003 Jam - designing a Java extension with mixins
abstract
In this paper we present Jam, an extension of the Java language supporting mixins , that is, parametric heir classes. A mixin declaration in Jam is similar to a Java heir class declaration, except that it does not extend a fixed parent class, but simply specifies the set of fields and methods a generic parent should provide. In this way, the same mixin can be instantiated on many parent classes, producing different heirs, thus avoiding code duplication and largely improving modularity and reuse. Moreover, as happens for classes and interfaces, mixin names are reference types, and all the classes obtained by instantiating the same mixin are considered subtypes of the corresponding type, and hence can be handled in a uniform way through the common interface. This possibility allows a programming style where different ingredients are "mixed" together in defining a class; this paradigm is somewhat similar to that based on multiple inheritance, but avoids its complication.The language has been designed with the main objective in mind to obtain, rather than a new theoretical language, a working and smooth extension of Java. That means, on the design side, that we have faced the challenging problem of integrating the Java overall principles and complex type system with this new notion; on the implementation side, it means that we have developed a Jam-to-Java translator which makes Jam sources executable on every Java Virtual Machine.
Davide Ancona, Giovanni Lagorio, Elena Zucca
ACM Trans. Program. Lang. Syst.2
2002 A Formal Framework for Java Separate Compilation
Davide Ancona, Giovanni Lagorio, Elena Zucca
ECOOP2
2002 True separate compilation of Java classes
abstract
We define a type system modeling true separate compilation for a small but significant Java subset, in the sense that a single class declaration can be intra-checked (following the Cardelli's terminology) and compiled providing a minimal set of type requirements on missing classes. These requirements are specified by a local type environment associated with each single class, while in the existing formal definitions of the Java type system classes are typed in a global type environment containing all the type information on a closed program. We also provide formal rules for static interchecking and relate our approach with compilation of closed programs, by proving that we get the same results.
Davide Ancona, Giovanni Lagorio, Elena Zucca
PPDP2
2001 A Core Calculus for Java Exceptions
abstract
In this paper we present a simple calculus (called CJE) in ourder to fully investigate the exception mechanism of Java, and in particular its interaction with inheritance, which turns out to be non trivial. Moreover, we show that the type system for the calculus directly dirven by the Java language specification (called FULL) uses too many types, in the sense that there are different types which rpovide exactly the same information. Hence, we obtain from FULL a simplified type system called MIN where equivalent types have been identified. We show that is useful both for type-checking optimization and for clarifying the static semantics of the language. The two type systems are proved to satisfy the subject reduction property
Davide Ancona, Giovanni Lagorio, Elena Zucca
OOPSLA2
2000 Jam - A Smooth Extension of Java with Mixins
Davide Ancona, Giovanni Lagorio, Elena Zucca
ECOOP2