EDBT 2026 Demo / reviewers in the wild / expert
Antonino Rullo
dblp:117/6994
· DBLP profile ↗
17ranked-venue papers
8as first author
7since 2021 · last 2026
0000-0002-6030-0027ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 first-authorComputer networks · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MalARN: An Adversarial Reconstruction Network for Improving Detection of Evolving Malware
Francesco Pasqualatto, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Giuseppe Manco 0001, Ettore Ritacco, Antonino Rullo |
ISMIS | 7 |
| 2026 | Seeing the invisible: Detection of stealth DoS attacks using variational U-Net-like modelsabstractThe increasing sophistication of cyberattacks targeting companies and organizations continues to challenge the effectiveness of modern defense systems. Among these threats, slow Denial-of-Service (slow DoS) attacks are particularly difficult to detect, as they rely on evasion strategies that add significant complexity to cybersecurity efforts. Modern intrusion detection systems, especially those based on deep learning, have become essential tools in combating such attacks. However, their performance is often hindered by challenges such as limited data availability, noisy inputs, and the presence of out-of-distribution samples. Furthermore, their dependence on large labeled datasets makes detecting subtle or rare attack patterns particularly challenging. To overcome these limitations, this work proposes a novel unsupervised deep learning framework for detecting slow DoS attacks. The proposed approach incorporates a customized preprocessing pipeline to improve input data quality and leverages a sparse variational U-Net-like architecture for robust anomaly identification. Extensive experiments conducted on three real-world datasets demonstrate the ability of the framework to accurately and efficiently detect slow DoS attacks, highlighting its robustness, generalizability, and practical suitability for deployment in operational environments. Enrico Cambiaso, Francesco Folino, Massimo Guarascio 0001, Angelica Liguori, Antonino Rullo |
J. Inf. Secur. Appl. | 5 |
| 2025 | PUF-Based Authentication-Oriented Architecture for Identification TagsabstractSmart tags are compact electronic devices affixed to or embedded into objects to facilitate identification, monitoring, and data exchange. Consequently, secure authentication of these tags is a crucial issue, as objects must reliably verify their identity before sharing sensitive information with other entities. The application of Physical Unclonable Functions (PUF) as a device's “digital fingerprint” has attracted significant attention, yet existing PUF-based authentication methods exhibit security vulnerabilities, either due to the authentication protocol itself or the limited reliability of the PUF technology used. Moreover, there has been a considerable focus on the software aspect, often overlooking the critical role of hardware design, which can become a target for attacks aimed at compromising the device's identity or act as a hindrance in the manufacturing process. In light of these points, this paper introduces an identification tag architecture that leverages PUF technology, focusing on authentication. This architecture features a straightforward but efficient authentication protocol, underpinned by a new and highly stable PUF model. The overall architecture encompasses particular hardware implementation aspects that significantly simplify the tag's enrollment phase and minimize vulnerabilities to attacks. The paper also describes a prototype of this identification tag and provide detailed insights into its application. Antonino Rullo, Carmelo Felicetti, Massimo Vatalaro, Raffaele De Rose, Marco Lanuzza, Felice Crupi, Domenico Saccà |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Kalis2.0 - A SECaaS-Based Context-Aware Self-Adaptive Intrusion Detection System for IoTabstractThe wide variety of application domains makes the Internet of Things (IoT) quite unique among other types of computer networks: IoT networks can be made of devices of different types, i.e., characterized by different hardware, functionalities, computing capabilities, and also network topology and communication protocols may drastically change from one IoT application to another. Such a heterogeneity requires ad-hoc security solutions, as security techniques that are effective in one IoT context may not be so in another context. Furthermore, IoT networks are ever-evolving by their very nature as smart devices can be easily added or removed. These factors call for the design of security tools capable of adapting themselves to the specific IoT instance, but also to the continuous network changes. In this paper we propose a context-aware, Security-as-a-Service based approach for intrusion detection whereby an IDS (i) autonomously collects information about the monitored system, (ii) chooses the best detection strategy accordingly, and (iii) modifies the detection strategy as the network evolves over time. This comprehensive approach to intrusion detection is an attempt to face the heterogeneity which characterizes the IoT in all its aspects, making it possible the design of a security tool able to be self-adaptive and context-aware, that is, effective in different and evolving IoT scenarios with little or no human intervention. Antonino Rullo, Daniele Midi, Anand Mudgerikar, Elisa Bertino |
IEEE Internet Things J. | 1 |
| 2023 | Guest Editorial Special Issue on Intrusion Detection for the Internet of ThingsabstractThe proliferation of IoT devices in everyday life has made their security a critical requirement. Currently, those devices are not secure enough because of several reasons. First, manufacturers do not account much for security, releasing products that are vulnerable to attacks, thus leaving security issues that are unlikely to be resolved. Second, many IoT devices lack the processing power to run antivirus software or even permit its installation. Finally, the heterogeneity, which characterizes the IoT in terms of applications, hardware, and software, expands the attack surface, while at the same time increasing the difficulty of deploying all-encompassing security solutions. Antonino Rullo, Elisa Bertino, Kui Ren 0001 |
IEEE Internet Things J. | 1 |
| 2021 | PUF-based Smart Tags for Supply Chain ManagementabstractCounterfeiting represents one of the most widespread phenomena at a global level that indiscriminately affects all product sectors, from fashion to food, from medicines to digital media. The fight against counterfeiting remains a significant challenge for industries. Most of the current supply chains rely on centralized authorities or intermediaries that are not sufficient robust to guarantee anti-counterfeiting and traceability of goods. Alberto Falcone, Carmelo Felicetti, Alfredo Garro, Antonino Rullo, Domenico Saccà |
ARES | 4 |
| 2021 | A multi-perspective approach for the analysis of complex business processes behavior
Antonella Guzzo, Mikel Joaristi, Antonino Rullo, Edoardo Serra |
Expert Syst. Appl. | 3 |
| 2020 | A Framework for the Multi-modal Analysis of Novel Behavior in Business Processes
Antonino Rullo, Antonella Guzzo, Edoardo Serra, Erika Tirrito |
IDEAL (1) | 1 |
| 2019 | Extending inverse frequent itemsets mining to generate realistic datasets: complexity, accuracy and emerging applications
Domenico Saccà, Edoardo Serra, Antonino Rullo |
Data Min. Knowl. Discov. | 3 |
| 2017 | Shortfall-Based Optimal Placement of Security Resources for Mobile IoT Scenarios
Antonino Rullo, Edoardo Serra, Elisa Bertino, Jorge Lobo 0001 |
ESORICS (2) | 1 |
| 2017 | Kalis - A System for Knowledge-Driven Adaptable Intrusion Detection for the Internet of ThingsabstractIn this paper, we introduce Kalis, a self-adapting, knowledge-driven expert Intrusion Detection System able to detect attacks in real time across a wide range of IoT systems. Kalis does not require changes to existing IoT software, can monitor a wide variety of protocols, has no performance impact on applications on IoT devices, and enables collaborative security scenarios. Kalis is the first comprehensive approach to intrusion detection for IoT that does not target individual protocols or applications, and adapts the detection strategy to the specific network features. Extensive evaluation shows that Kalis is effective and efficient in detecting attacks to IoT systems. Daniele Midi, Antonino Rullo, Anand Mudgerikar, Elisa Bertino |
ICDCS | 2 |
| 2017 | Shortfall-Based Optimal Security Provisioning for Internet of ThingsabstractWe present a formal method for computing the best security provisioning for Internet of Things (IoT) scenarios characterized by a high degree of mobility. The security infrastructure is intended as a security resource allocation plan, computed as the solution of an optimization problem that minimizes the risk of having IoT devices not monitored by any resource. We employ the shortfall as a risk measure, a concept mostly used in the economics, and adapt it to our scenario. We show how to compute and evaluate an allocation plan, and how such security solutions address the continuous topology changes that affect an IoT environment. Antonino Rullo, Edoardo Serra, Elisa Bertino, Jorge Lobo 0001 |
ICDCS | 1 |
| 2017 | Pareto Optimal Security Resource Allocation for Internet of ThingsabstractIn many Internet of Thing (IoT) application domains security is a critical requirement, because malicious parties can undermine the effectiveness of IoT-based systems by compromising single components and/or communication channels. Thus, a security infrastructure is needed to ensure the proper functioning of such systems even under attack. However, it is also critical that security be at a reasonable resource and energy cost. In this article, we focus on the problem of efficiently and effectively securing IoT networks by carefully allocating security resources in the network area. In particular, given a set of security resources R and a set of attacks to be faced A , our method chooses the subset of R that best addresses the attacks in A , and the set of locations where to place them, that ensure the security coverage of all IoT devices at minimum cost and energy consumption. We model our problem according to game theory and provide a Pareto-optimal solution in which the cost of the security infrastructure, its energy consumption, and the probability of a successful attack are minimized. Our experimental evaluation shows that our technique improves the system robustness in terms of packet delivery rate for different network topologies. Furthermore, we also provide a method for handling the computation of the resource allocation plan for large-scale networks scenarios, where the optimization problem may require an unreasonable amount of time to be solved. We show how our proposed method drastically reduces the computing time, while providing a reasonable approximation of the optimal solution. Antonino Rullo, Daniele Midi, Edoardo Serra, Elisa Bertino |
ACM Trans. Priv. Secur. | 1 |
| 2017 | Malevolent Activity Detection with Hypergraph-Based ModelsabstractWe propose a hypergraph-based framework for modeling and detecting malevolent activities. The proposed model supports the specification of order-independent sets of action symbols along with temporal and cardinality constraints on the execution of actions. We study and characterize the problems of consistency checking, equivalence, and minimality of hypergraph-based models. In addition, we define and characterize the general activity detection problem, that amounts to finding all subsequences that represent a malevolent activity in a sequence of logged actions. Since the problem is intractable, we also develop an index data structure that allows the security expert to efficiently extract occurrences of activities of interest. Antonella Guzzo, Andrea Pugliese 0001, Antonino Rullo, Domenico Saccà, Antonio Piccolo |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2016 | Strategic Security Resource Allocation for Internet of ThingsabstractIn many Internet of Thing (IoT) application domains security is a critical requirement, because malicious parties can undermine the effectiveness of IoT-based systems by compromising single components and/or communication channels. Thus, a security infrastructure is needed to ensure the proper functioning of such systems even under attack. In this paper, we focus on the problem of efficiently and effectively securing IoT networks by carefully allocating security tools. Antonino Rullo, Daniele Midi, Edoardo Serra, Elisa Bertino |
ICDCS | 1 |
| 2015 | Pareto-Optimal Adversarial Defense of Enterprise SystemsabstractThe National Vulnerability Database (NVD) maintained by the US National Institute of Standards and Technology provides valuable information about vulnerabilities in popular software, as well as any patches available to address these vulnerabilities. Most enterprise security managers today simply patch the most dangerous vulnerabilities—an adversary can thus easily compromise an enterprise by using less important vulnerabilities to penetrate an enterprise. In this article, we capture the vulnerabilities in an enterprise as a Vulnerability Dependency Graph (VDG) and show that attacks graphs can be expressed in them. We first ask the question: What set of vulnerabilities should an attacker exploit in order to maximize his expected impact? We show that this problem can be solved as an integer linear program. The defender would obviously like to minimize the impact of the worst-case attack mounted by the attacker—but the defender also has an obligation to ensure a high productivity within his enterprise. We propose an algorithm that finds a Pareto-optimal solution for the defender that allows him to simultaneously maximize productivity and minimize the cost of patching products on the enterprise network. We have implemented this framework and show that runtimes of our computations are all within acceptable time bounds even for large VDGs containing 30K edges and that the balance between productivity and impact of attacks is also acceptable. Edoardo Serra, Sushil Jajodia, Andrea Pugliese 0001, Antonino Rullo, V. S. Subrahmanian |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2014 | PADUA: Parallel Architecture to Detect Unexplained ActivitiesabstractThere are numerous applications (e.g., video surveillance, fraud detection, cybersecurity) in which we wish to identify unexplained sets of events. Most related past work has been domain-dependent (e.g., video surveillance, cybersecurity) and has focused on the valuable class of statistical anomalies in which statistically unusual events are considered. In contrast, suppose there is a set A of known activity models (both harmless and harmful) and a log L of time-stamped observations. We define a part L '⊆ L of the log to represent an unexplained situation when none of the known activity models can explain L ' with a score exceeding a user-specified threshold. We represent activities via probabilistic penalty graphs (PPGs) and show how a set of PPGs can be combined into one Super-PPG for which we define an index structure. Given a compute cluster of ( K + 1) nodes (one of which is a master node), we show how to split a Super-PPG into K subgraphs, each of which can be independently processed by a compute node. We provide algorithms for the individual compute nodes to ensure seamless handoffs that maximally leverage parallelism. PADUA is domain-independent and can be applied to many domains (perhaps with some specialization). We conducted detailed experiments with PADUA on two real-world datasets—the ITEA CANDELA video surveillance dataset and a network traffic dataset appropriate for cybersecurity applications. PADUA scales extremely well with the number of processors and significantly outperforms past work both in accuracy and time. Thus, PADUA represents the first parallel architecture and algorithm for identifying unexplained situations in observation data, offering both scalability and accuracy. Cristian Molinaro, Vincenzo Moscato, Antonio Picariello, Andrea Pugliese 0001, Antonino Rullo, V. S. Subrahmanian |
ACM Trans. Internet Techn. | 5 |