Alessandra De Benedictis

dblp:10/11350 · DBLP profile ↗
← Back
41ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0001-7455-4653ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 10 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 4 first-author · 6 since 2021Computer networks · 5 · 3 since 2021Security and privacy · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Systems, architecture and hardware · 3Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TwinArch: A digital twin reference architecture
Alessandra Somma, Domenico Amalfitano, Alessandra De Benedictis, Patrizio Pelliccione
J. Syst. Softw.3
2025 A Moving Target Defense Framework to Improve Resilience of Cloud-Edge Systems
Valentina Casola, Alessandra De Benedictis, Daniele Iorio, Salvatore Migliaccio
AINA (6)2
2025 Methodologies and tools for quantitative risk assessment including the human factor analysis: a railway case study
abstract
The railway sector is vital for transporting people and goods, necessitating high safety and reliability standards. The increasing complexity of railway systems, with new technologies and automation, requires effective risk management strategies. Risk Assessment systematically identifies, analyzes, and mitigates hazards from technical failures, human errors, and environmental factors, aiming to maintain safety and resilience.Digitalization and automation have heightened the importance of Risk Assessment, introducing vulnerabilities like programming errors and cyber-attacks. The human factor remains critical, influencing safety through decisions, risk perception, and adherence to procedures. Technological advancements have reduced mechanical failures, but human errors, such as incorrect decisions and fatigue, are now major causes of accidents.The study, in collaboration with Hitachi Rail STS, aims to quantitatively assess risks in metro systems, including human factors, using specialized tools for risk evaluation and fault tree generation.
Pasquale Carusone, Alessandra De Benedictis, Diego Gerbasio
SMC2
2025 A model-driven approach for engineering Mobility Digital Twins: The Bologna case study
abstract
As cities grapple with increasing congestion, sustainability concerns, and the need for efficient mobility systems, Mobility Digital Twins (MoDTs) have emerged as promising technology for improving urban transportation. However, the development of MoDTs remains hindered by challenges such as structural complexity, data heterogeneity, lack of interoperability, and limited support for scalability, maintainability, and adaptability. This work aims to address these barriers by introducing a structured and systematic engineering framework that supports the design development of MoDT, reducing technical debt, development costs and human errors, while promoting long-term evolution. We propose a Model-Driven Engineering (MDE) approach that organizes the development of MoDTs through models at different levels of abstraction and adopts automated transformations from high-level specifications to executable code artifacts, supporting MoDT life-cycle. The proposed approach is validated through its application in developing a MoDT for the city of Bologna, Italy. To support this, we introduce the M2DT tool, which automates the workflow from high-level models to software code artifacts. The resulting BoMoDT platform is built using open-source technologies and real mobility data. This case study demonstrates the feasibility and effectiveness of our approach, which, to our knowledge, is the first to apply a model-driven strategy for the entire MoDT development. A qualitative evaluation confirms that our framework addresses key challenges in MoDT development. Quantitative experiments further validate BoMoDT’s ability to accurately reproduce and monitor real urban mobility conditions. The proposed approach offers a solid foundation for addressing MoDT development challenges. By combining automation with structured abstraction, it improves adaptability and maintainability while enabling scalable integration, helping make MoDTs more accessible for future urban system design. • Six challenges in Mobility Digital Twins are identified from literature analysis. • A model-driven approach is introduced to structure their development. • The approach is applied to real world urban mobility case study. • BoMoDT is presented as DT platform for simulation and monitoring of Bologna mobility. • Fidelity and responsiveness are quantitatively evaluated.
Alessandra Somma, Domenico Amalfitano, Alessio Bucaioni, Alessandra De Benedictis
Inf. Softw. Technol.4
2024 DEFEDGE: Threat-Driven Security Testing and Proactive Defense Identification for Edge-Cloud Systems
Valentina Casola, Marta Catillo, Alessandra De Benedictis, Felice Moretta, Antonio Pecchia, Massimiliano Rak, Umberto Villano
AINA (5)3
2024 A Digital Twin Architecture for Intelligent Public Transportation Systems: A FIWARE-Based Solution
Alessandra De Benedictis, Franca Rocco di Torrepadula, Alessandra Somma
W2GIS1
2024 Secure software development and testing: A model-based methodology
abstract
Modern industries widely rely upon software and IT services, in a context where cybercrime is rapidly spreading in more and more sectors. Unfortunately, despite greater general awareness of security risks and the availability of security tools that can help to cope with those risks, many organizations (especially medium/small-size ones) still lag when it comes to building security into their services. This is mainly due to the limited security skills of common developers/IT project managers and to the typically high costs of security procedures. In fact, while automated tools exist to perform code analysis, vulnerability scanning, or security testing, the manual intervention of security experts is still required not only for security analysis and design, but also to configure and elaborate the output of the security testing tools. In this paper, we propose a novel secure software development methodology aimed at supporting developers from security design to security testing, suitable for integration within modern DevOps pipelines according to a DevSecOps (or SecDevOps) approach. The proposed methodology leverages a model-based process that enables identifying existing threats, selecting appropriate countermeasures to enforce, and verify their mitigation effectiveness through both static assessment procedures and targeted security tests. To demonstrate our approach's feasibility and concretely illustrate the devised activities, we provide a step-by-step description of the whole process concerning a containerized microservice-based application case study. In addition, we discuss the application of the proposed methodology, in its threat modeling and security testing phases, to a well-known vulnerable web application widely used for security training purposes, to illustrate that we can identify most of the existing vulnerabilities and determine appropriate test plans to assess and mitigate such vulnerabilities.
Valentina Casola, Alessandra De Benedictis, Carlo Mazzocca, Vittorio Orbinato
Comput. Secur.2
2024 The convergence of Digital Twins and Distributed Ledger Technologies: A systematic literature review and an architectural proposal
abstract
In recent years, the emerging Digital Twin (DT) technology is playing a key role in fostering the transition towards the Industry 4.0. DTs, representing virtual replicas of physical objects, products or processes established thanks to a bidirectional continuous flow of information between the physical and the virtual world, are currently adopted in multiple domains such as manufacturing, aerospace, automotive, energy, construction, smart cities and smart mobility, etc.. DTs live together with the physical system they replicate, receiving the same data and often triggering specific control actions that directly impact on the real system status. When dealing with DTs of complex Cyber-Physical Systems (CPSs), the data sources may be heterogeneous and untrustworthy, which requires the DT to be able to address security issues related to data in transit from/to the physical twin and data at rest. A possible way to address these data security issues consists in adopting Distributed Ledger Technologies (DLTs) which provide several security guarantees on data through cryptographic hashing techniques. In this work, we present a three-fold contribution: (i) we discuss the results of a Systematic Literature Review (SLR) on the state-of-the-art of the research related to the integration between DLT and Digital Twins, aimed at clarifying relevant aspects such as, among others, what is the favourite DLT choice in existing proposals or what is the type of DT-related information to store on-chain; (ii) leveraging the SLR results and other related research, we propose an architectural framework for the integration of DT and DLTs (more specifically, blockchains); (iii) we validate the proposed architecture by means of two proof-of-concept implementations leveraging different technological stacks and taking into account two different operational scenarios. Finally, we conduct a requirements coverage analysis and compare the PoCs through a coverage matrix.
Alessandra Somma, Alessandra De Benedictis, Christian Esposito 0001, Nicola Mazzocca
J. Netw. Comput. Appl.2
2023 Digital Twin Space: The Integration of Digital Twins and Data Spaces
abstract
Digital Twins (DTs) are the novel paradigm for the development of Cyber-Physical systems. The state of art presents several use cases in different domains, and one of the most complex examples is represented by the Urban Digital Twin (UDT), which aims to virtualize urban assets (e.g., buildings, mobility infrastructures, energy grids, waste management facilities, etc.) and build advanced analysis and prediction services upon a city’s digital representation. UDTs represent a formidable example of system of systems, as they are structured into a hierarchy of interconnected DT instances that process and share a huge amount of data subject to different access and usage policies.Regarding data management in complex distributed scenarios, Data Spaces are an emerging paradigm that aims at building a secure and privacy-preserving infrastructure to pool, access, share, process and use data. As a matter of fact, existing DTs solutions (not only in the urban domain) do not present a clear software architecture characterization and, moreover, they pay little attention to the data management aspects.To bridge this gap, in this paper we present the Digital Twin Space, an architectural proposal that aims to instantiate Data Spaces into DTs according to the guidelines set by relevant international projects. We use the UDT as a running example and we validate the model in the case of a smartPV panel, showing that the model matches the real cyber-physical system.
Alessandra Somma, Alessandra De Benedictis, Marco Zappatore, Cristian Martella, Angelo Martella, Antonella Longo
IEEE Big Data2
2023 Digital Twins for Anomaly Detection in the Industrial Internet of Things: Conceptual Architecture and Proof-of-Concept
abstract
Modern cyber-physical systems based on the Industrial Internet of Things (IIoT) can be highly distributed and heterogeneous, and that increases the risk of failures due to misbehavior of interconnected components, or other interaction anomalies. In this paper, we introduce a conceptual architecture for IIoT anomaly detection based on the paradigms of Digital Twins (DT) and Autonomic Computing (AC), and we test it through a proof-of-concept of industrial relevance. The architecture is derived from the current state-of-the-art in DT research and leverages on the MAPE-K feedback loop of AC in order to monitor, analyze, plan, and execute appropriate reconfiguration or mitigation strategies based on the detected deviation from prescriptive behavior stored as shared knowledge. We demonstrate the approach and discuss results by using a reference operational scenario of adequate complexity and criticality within the European Railway Traffic Management System.
Alessandra De Benedictis, Francesco Flammini, Nicola Mazzocca, Alessandra Somma, Francesco Vitale
IEEE Trans. Ind. Informatics1
2023 Digital Twins in Healthcare: An Architectural Proposal and Its Application in a Social Distancing Case Study
abstract
The digital transformation process fostered by the development of Industry 4.0 technologies has largely affected the health sector, increasing diagnostic capabilities and improving drug effectiveness and treatment delivery. The Digital Twin (DT) technology, based on the virtualization of physical assets/processes and on a bidirectional communication between the digital and physical space for data exchange, is considered a game changer in modern health systems. Digital Twin applications in healthcare are various, ranging from virtualization of hospitals' physical spaces/organizational processes to individuals' physiological/genetic/lifestyle characteristics replication, and include the modeling of public health-related processes for monitoring, optimization and planning purposes. In this paper, motivated by the current COVID-19 pandemic, we focus on the application of the Digital Twin technology for virus containment on the workplace through social distancing. The contribution of this paper is three-fold: i) we review the existing literature on the adoption of the Digital Twin technology in the healthcare domain, and propose a classification of DT applications into four categories; ii) we propose a generalized Digital Twin architecture that can be used as reference to identify the main functional components of a Digital Twin system; iii) we present CanTwin, a real-life industrial case study developed by Hitachi and representing the Digital Twin of a canteen service serving 1100 workers, set up for social distancing monitoring, queue inspection, people counting and tracking, table occupancy supervision.
Alessandra De Benedictis, Nicola Mazzocca, Alessandra Somma, Carmine Strigaro
IEEE J. Biomed. Health Informatics1
2021 Security-Aware Deployment Optimization of Cloud-Edge Systems in Industrial IoT
abstract
Cloud computing, edge computing, and the Internet of Things are significantly changing from the original architectural models with pure provisioning of virtual resources (and services) to a transparent and adaptive hosting environment, where cloud providers, as well as “on-premise” resources and end nodes, fully realize the “everything-as-a-service” provisioning concept. The optimal design of these architectures, including the selection of optimal services to acquire, is not trivial in the cloud-edge context due to the involvement of a variable number and the type of available resources offerings and to the impact on cost, performance, and other relevant features such as security, almost never considered. This article presents a novel formalization of the cloud-edge allocation problem for the industrial IoT context. The proposed optimization process takes explicitly into account two critical aspects that are often overlooked in similar approaches, namely, the new cloud-edge on-demand service offerings model for the allocation of resources and the impact on the deployed application, in terms of cost, performance, and security policies actually implemented. An efficient yet suboptimal deterministic solver is also presented and compared with a linear programming one. Results are the same in 86% of the cases on the considered data set while our solver is orders of magnitude faster than the linear one.
Valentina Casola, Alessandra De Benedictis, Sergio Di Martino, Nicola Mazzocca, Luigi L. L. Starace
IEEE Internet Things J.2
2021 On the Adoption of Physically Unclonable Functions to Secure IIoT Devices
abstract
The growing convergence among information and operation technology worlds in modern Industrial Internet of Things (IIoT) systems is posing new security challenges, requiring the adoption of novel security mechanisms involving light architectures and protocols to cope with IIoT devices resource constraints. In this article, we investigate the adoption of physically unclonable functions (PUFs) in the IIoT context, and propose the design of a PUF-based architecture (Pseudo-PUF), obtained by suitably combining a weak PUF and an encryption module, that can be successfully adopted to implement advanced security primitives while meeting the existing requirements of IIoT devices in terms of cost and resource demand. To demonstrate the feasibility of our proposal, we analyzed the overall quality of different Pseudo-PUF instances with respect to well-known PUF quality metrics, and found that it is possible to obtain good results with a negligible impact on the devices, thus making our approach suited to IIoT deployments.
Mario Barbareschi, Valentina Casola, Alessandra De Benedictis, Erasmo La Montagna, Nicola Mazzocca
IEEE Trans. Ind. Informatics3
2021 A Security and Privacy Validation Methodology for e-Health Systems
abstract
e-Health applications enable one to acquire, process, and share patient medical data to improve diagnosis, treatment, and patient monitoring. Despite the undeniable benefits brought by the digitization of health systems, the transmission of and access to medical information raises critical issues, mainly related to security and privacy. While several security mechanisms exist that can be applied in an e-Health system, they may not be adequate due to the complexity of involved workflows, and to the possible inherent correlation among health-related concepts that may be exploited by unauthorized subjects. In this article, we propose a novel methodology for the validation of security and privacy policies in a complex e-Health system, that leverages a formal description of clinical workflows and a semantically enriched definition of the data model used by the workflows, in order to build a comprehensive model of the system that can be analyzed with automated model checking and ontology-based reasoning techniques. To validate the proposed methodology, we applied it to two case studies, subjected to the directives of the EU GDPR regulation for the protection of health data, and demonstrated its ability to correctly verify the fulfillment of desired policies in different scenarios.
Flora Amato, Valentina Casola, Giovanni Cozzolino, Alessandra De Benedictis, Nicola Mazzocca, Francesco Moscato 0001
ACM Trans. Multim. Comput. Commun. Appl.4
2020 Security and trust in cloud application life-cycle management
Massimiliano Albanese, Alessandra De Benedictis, Douglas Dyllon Jeronimo de Macedo, Fabrizio Messina
Future Gener. Comput. Syst.2
2020 Exploiting Workflow Languages and Semantics for Validation of Security Policies in IoT Composite Services
abstract
Internet of Things (IoT) ecosystems are recently experiencing a significant growth in complexity. Most IoT applications in domains like healthcare, industry, automotive, and smart energy are composed of several interconnected subsystems that produce, collect, process, and exchange a huge amount of data, and that offer composite services to the end users based on these data. This scenario is exacerbated by the dynamism of the IoT device layer, which may be subject to structural or technological changes over time, to cope for example with the need for new sensing/actuation capabilities requirements or with technical issues. Due to the inherent sensitive nature of the data that is typically processed by IoT applications, security represents one of the primary issues to address. It is worth noting that each subsystem integrated within a composite IoT application may have different requirements and enforce different local security policies, and the policies that result globally enforced at the system level may not comply with the existing global requirements. In general, the analysis and validation of security properties in a composite IoT system represents a very complex task, made even more complex by the introduction of new laws and regulations during system life. To cope with the above issues, in this article, we propose a methodology that leverages both workflow languages and semantics in order to enable the validation of the security features offered by a composite IoT system, with the goal of verifying whether they match with global end-user policies and even with national and international laws and rules.
Flora Amato, Valentina Casola, Giovanni Cozzolino, Alessandra De Benedictis, Francesco Moscato 0001
IEEE Internet Things J.4
2020 A novel Security-by-Design methodology: Modeling and assessing security by SLAs with a quantitative approach
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
J. Syst. Softw.2
2019 PUF-Enabled Authentication-as-a-Service in Fog-IoT Systems
abstract
Fog-IoT systems enable to distribute computing, control, storage, and networking functions closer to edge devices, in order to improve efficiency and reduce latency. In order to cope with the multitude of security issues raised by the lack of centralized control and by the exposure of user sensitive data, suitable security solutions must be devised to protect data and thwart malicious attempts to compromise and take control over communication. In this paper, we propose a mutual authentication scheme relying upon the adoption of Physically Unclonable Functions (PUFs), which enables fog nodes and resource-constrained IoT devices to mutually prove their respective identities during communication, while meeting the existing low resource consumption requirements. The scheme is partially offered in an as-a-service fashion, thanks to the adoption of a cloud automation framework that facilitates its set-up on fog nodes.
Mario Barbareschi, Alessandra De Benedictis, Erasmo La Montagna, Antonino Mazzeo, Nicola Mazzocca
WETICE2
2019 Enabling Technologies: Infrastructure for Collaborative Enterprises Editorial for WETICE 2019 Conference
abstract
The International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises WETICE is an international forum for state-of the-art research in enabling technologies for collaboration. The 28th WETICE edition takes place on June 12-14, 2019 in Capri (Napoli), Italy and it is made of eleven scientific tracks.
Valentina Casola, Alessandra De Benedictis, Umberto Villano
WETICE2
2019 A First Step Towards an ISO-Based Information Security Domain Ontology
abstract
The need for Information Security Management Systems (SIEMs) has increased the effort requested to companies to improve the security level of their systems and their compliance with national and international standards. Unfortunately, the existence of several different security standards to comply with and the lack of well-defined guidelines related to documents preparation and reporting, may result into a bad security management and may cause several security issues. In this paper, we introduce a modeling approach to the definition of a SIEM that leverages a double-layered ontology: it is composed of a highlevel ontology, used to model complex relations among domains, and of a low-level, domain-specific ontology, aimed at modeling the ISO 27000 family of standards.
Valentina Casola, Rosario Catelli, Alessandra De Benedictis
WETICE3
2019 A PUF-based mutual authentication scheme for Cloud-Edges IoT systems
Mario Barbareschi, Alessandra De Benedictis, Erasmo La Montagna, Antonino Mazzeo, Nicola Mazzocca
Future Gener. Comput. Syst.2
2018 A Proposal of a Cloud-Oriented Security and Performance Simulator Provided as-a-Service
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
CISIS2
2018 A Model-Based Evaluation Methodology for Smart Energy Systems
abstract
The huge amount of data collected everyday for different purposes by a multitude of smart devices enables the delivery of added-value services to end-users by means of smart applications. Among them, the applications devoted to optimizing the energy consumption through smart power grids are gaining more and more attention due to their impact on both the environment and the costs for the users. The design and evaluation of Smart Energy systems is very complex due to the heterogeneity of involved devices and technologies, and to the high variability of energy production and consumption profiles. In this regard, in this paper we propose a model-based methodology for the evaluation of Smart Energy systems, which merges system modeling and cognitive computing techniques to obtain a representation of the systems' behavior that takes into account a data-driven characterization of the workload and of the overall context. Such a representation allows to estimate properties of interest in different operative conditions, and can be profitably used to make design choices and to tune the application behavior during operation based on collected data. In order to demonstrate the effectiveness of our proposal, we present an example Smart Energy system modeled by means of the Stochastic Activity Network (SAN) formalism, and we show how it is possible to perform several analyses on the system configuration by means of model simulations.
Alessandra De Benedictis, Nicola Mazzocca, Roberto Nardone, Salvatore Venticinque
SMARTCOMP1
2018 Towards Automated Penetration Testing for Cloud Applications
abstract
The development of cloud applications raises several security concerns due to the lack of control over involved resources. Security testing is fundamental to identify the existing security issues and is particularly powerful when carried out by means of penetration testing techniques. Unfortunately, penetration testing requires a deep knowledge of the possible attacks and of the available hacking tools and is very energy demanding. In this paper, we present a methodology that allows to easily carry out a coarse-grained security evaluation of a cloud application by automating the set-up and execution of penetration tests. The methodology relies on the knowledge of the application architecture and on the availability of a catalogue including security-related data collected from multiple sources and properly correlated.
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
WETICE2
2018 Security-by-design in multi-cloud applications: An optimization approach
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
Inf. Sci.2
2018 A PUF-based hardware mutual authentication protocol
Mario Barbareschi, Alessandra De Benedictis, Nicola Mazzocca
J. Parallel Distributed Comput.2
2017 A Security Metric Catalogue for Cloud Applications
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
CISIS2
2017 An Automatic Tool for Benchmark Testing of Cloud Applications
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
CLOSER2
2017 Towards Model-Based Security Assessment of Cloud Applications
Valentina Casola, Alessandra De Benedictis, Roberto Nardone
GPC2
2017 MUSA Deployer: Deployment of Multi-cloud Applications
abstract
The development of applications based on services offered by different, not conscious, providers, is expected to be growing in the next years. In order to offer effectively multicloud applications, many challenges still need to be faced. At this aim, the MUSA framework provides a DevOps approach to develop multi-cloud applications with desired Security Service Level Agreements (SLAs). This paper describes the MUSA Deployer models, which help developers to express their security requirements, and a Deployer tool that automatically provides cloud security services to offer Security SLAs.
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano, Erkuden Rios, Angel Rego, Giancarlo Capone
WETICE2
2017 Automatically Enforcing Security SLAs in the Cloud
abstract
Dealing with the provisioning of cloud services granted by Security SLAs is a very challenging research topic. At the state of the art, the main related issues involve: (i) representing security features so that they are understandable by both customers and providers and measurable (by means of verifiable security-related Service Level Objectives (SLOs)), (ii) automating the provisioning of security mechanisms able to grant desired security features (by means of a security-driven resource allocation process), and (iii) continuously monitoring the services in order to verify the fulfillment of specified Security SLOs (by means of cloud security monitoring solutions). We propose to face the Security SLA life cycle management with a framework able to enrich cloud applications with security features. In this paper we (i) present a novel Security SLA model and (ii) illustrate a security-driven planning process that can be adopted to determine the (optimum) deployment of security-related software components. Such process takes into account both specific implementation constraints of the security components to be deployed and customers security requirements, and enables the automatic provisioning and configuration of all needed resources. In order to demonstrate the applicability of the approach, we present and discuss a practical application of the model on a real case study.
Valentina Casola, Alessandra De Benedictis, Madalina Erascu, Jolanda Modic, Massimiliano Rak
IEEE Trans. Serv. Comput.2
2016 A Security SLA-driven Methodology to Set-Up Security Capabilities on Top of Cloud Services
abstract
The extensive use of cloud services by both individual users and organizations induces several security risks. The risk perception is higher when Cloud Service Providers (CSPs) do not clearly state their security policies and/or when such policies do not directly match user-defined requirements. Security-oriented Service Level Agreements (Security SLAs) represent a fundamental means to encourage the adoption of cloud services in contexts where security is mandatory. Nevertheless, despite the number of existing initiatives aimed at formalizing Security SLAs and at representing security guarantees by taking into account both customers' and providers' perspectives, they are far from being commonly adopted in practice by CSPs, due to the difficulty in automatically enforcing and monitoring the security capabilities agreed with customers. In this paper we illustrate, through a case study, a methodology to set-up a catalogue of security capabilities that can be offered as-a-service, on top of which specific guarantees can be specified through a Security SLA. Such a methodology, which explicitly takes into account the constraints behind the definition of formal guarantees related to security, is meant to serve as a guideline for providers willing to offer for their services specific security features that can be monitored and assessed by customers during operation.
Valentina Casola, Alessandra De Benedictis, Madalina Erascu, Massimiliano Rak, Umberto Villano
CISIS2
2016 Per-Service Security SLa: A New Model for Security Management in Clouds
abstract
In the cloud computing context, Service Level Agreements (SLAs) are contracts between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs), stating the guaranteed quality level of the services offered by CSPs. Existing cloud SLAs focus only on few service terms, completely ignoring all security related aspects. They are often reported in a way that is hardly understandable for customers. Moreover, they offer guarantees uniform for all offered services and all customers, regardless of particular service characteristics or customers specific needs. This paper presents a framework that enables the adoption of a per-service SLA model, by supporting the automatic implementation of cloud Security SLAs tailored to the needs of each customer for specific service instances. In particular, the process and the software architecture for per-service SLA implementation are shown. A case study application demonstrates the feasibility and effectiveness of the proposed solution.
Valentina Casola, Alessandra De Benedictis, Jolanda Modic, Massimiliano Rak, Umberto Villano
WETICE2
2015 Security Monitoring in the Cloud: An SLA-Based Approach
abstract
In this paper we present a monitoring architecture that is automatically configured and activated based on a signed Security SLA. Such monitoring architecture integrates different security-related monitoring tools (either developed ad-hoc or already available as open-source or commercial products) to collect measurements related to specific metrics associated with the set of security Service Level Objectives (SLOs) that have been specified in the Security SLA. To demonstrate our approach, we discuss a case study related to detection and management of vulnerabilities and illustrate the integration of the popular open source monitoring system Open VAS into our monitoring architecture. We show how the system is configured and activated by means of available Cloud automation technologies and provide a concrete example of related SLOs and metrics.
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak
ARES2
2015 REST-Based SLA Management for Cloud Applications
abstract
In cloud computing, possible risks linked to availability, performance and security can be mitigated by the adoption of Service Level Agreements (SLAs) formally agreed upon by cloud service providers and their users. This paper presents the design of services for the management of cloud-oriented SLAs that hinge on the use of a REST-based API. Such services can be easily integrated into existing cloud applications, platforms and infrastructures, in order to support SLA-based cloud services delivery. After a discussion on the SLA life-cycle, an agreement protocol state diagram is introduced. It takes explicitly into account negotiation, remediation and renegotiation issues, is compliant with all the active standards, and is compatible with the WS-Agreement standard. The requirement analysis and the design of a solution able to support the proposed SLA protocol is presented, introducing the REST API used. This API aims at being the basis for a framework to build SLA-based applications.
Alessandra De Benedictis, Massimiliano Rak, Mauro Turtur, Umberto Villano
WETICE1
2014 Preliminary Design of a Platform-as-a-Service to Provide Security in Cloud
abstract
Cloud computing is an emerging paradigm, recently widely adopted in distributed and business computing. Even if it is very attractive, due to its business model (pay-per-use) and its flexibility (self-service on demand approach), one of the main limits for its adoption is the perception of loss of security and control over resources that are dynamically acquired in the cloud and that reside on remote providers. Moreover, security mechanisms are usually integrated into system architectures, and are not offered to users in a way that enables customization and is easy to use. As a consequence, as far as security is concerned, cloud customers are usually tied to a limited set of offerings made available by providers, often without real grants about the way in which such mechanisms are actually implemented and enforced. This paper deals with the architecture underlying the SPECS platform, which aims at offering security features by an as-a-service approach, using Service Level Agreements as a mean for clear statement between customers and providers to define mutual rights and constraints. The goal is to show the main requirements of such platform and to present the global architecture, in terms of components and their interactions, dedicated to negotiate, to monitor and to enforce the security mechanisms to be applied over existing cloud providers.
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano
CLOSER2
2014 Cloud-Aware Development of Scientific Applications
abstract
The potential of cloud computing is still underutilized in the scientific computing field. Even if clouds probably are not fit for high-end HPC applications, they could be profitably used to bring the power of economic and scalable parallel computing to the masses. But this requires simple and friendly development environments, able to exploit cloud scalability and to provide fault tolerance. This paper presents a framework built on the top of a cloud-aware platform (mOSAIC) for the development of bag-of-tasks scientific applications.
Alessandra De Benedictis, Massimiliano Rak, Mauro Turtur, Umberto Villano
WETICE1
2014 A probabilistic framework for jammer identification in MANETs
Massimiliano Albanese, Alessandra De Benedictis, Sushil Jajodia, Don J. Torrieri
Ad Hoc Networks2
2013 An SLA-Based Approach to Manage Sensor Networks as-a-Service
abstract
The integration of sensing infrastructures into the Cloud gives a number of advantages in providing sensor data as a service over the Internet. Many solutions are now available in the literature, and most of them focus on modeling sensor networks as part of the infrastructure to be offered as a service (IaaS), directly managed by means of the Cloud tools that provide resource virtualization. We propose a different approach: sensor networks are modeled as providers that offer their resources to a Cloud application that runs independently from Cloud providers. Being offered as a Service, any user can negotiate with the provider his desired requirements in terms of operational parameters and non-functional features (i.e. security, dependability, etc). In particular, we propose a SLA-based approach for the specification and management of usage term guarantees related to the access and configuration of private sensor networks. To this end, a Cloud Sensing Brokering Platform is designed to illustrate the innovative way to integrate Cloud and Sensor Networks.
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Giuseppe Aversano, Umberto Villano
CloudCom (1)2
2012 A Probabilistic Framework for Localization of Attackers in MANETs
Massimiliano Albanese, Alessandra De Benedictis, Sushil Jajodia, Paulo Shakarian
ESORICS2
2010 Securing a tiered re-taskable sensing system
abstract
Sensor Networks are widely used in several application domains thanks to their data acquisition and data processing capabilities. They are well suited to a multitude of monitoring and surveillance applications and are often involved in mission-critical tasks, thus making security a primary concern. Many architectures and protocols have been proposed to address this issue, mainly based on cryptographic operations, but it still represents an open research area: such techniques in fact, to be effective, often require complex computations and a large amount of dedicated resources, which are not available on sensor platforms according to the existing technology. Nevertheless, if considering tiered sensor networks, where tiny motes coexist with more powerful nodes, it is possible to perform some complex and efficient security schemes by exploiting the different capabilities of such nodes. In this paper we present an secure architectural proposal of the Tenet system, a tiered re-taskable sensor network architecture. Specifically, we have integrated some security library into the Tenet architecture in order to implement a hybrid cryptosystem. The latter combines symmetric and asymmetric cryptographic schemes to benefit of the security provided by asymmetric protocols and the better performance of symmetric ones.
Alessandra De Benedictis, Andrea Gaglione, Nicola Mazzocca
IAS1