EDBT 2026 Demo / reviewers in the wild / expert
Andrea Saracino
dblp:119/6683
· DBLP profile ↗
41ranked-venue papers
3as first author
15since 2021 · last 2026
0000-0001-8149-9322ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 2 first-author · 7 since 2021Computer networks · 6 · 1 first-author · 2 since 2021Systems, architecture and hardware · 5 · 3 since 2021Artificial intelligence and machine learning · 4 · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On-device derivation of IoT usage control policies: Automating U-XACML policy generation from natural language with LLMs in smart homes environmentsabstractIn this paper, we present a framework that integrates AI-based derivation of Access and Usage Control policies for IoT devices, using Large Language Models (LLMs) to automate the generation of policies from unstructured natural language commands. The framework employs a hybrid approach, combining LLMs with dedicated libraries to ensure efficient on-device execution. Our approach is based on a two-step process: first, a fine-tuned LLM converts user commands into structured JSON policy representations; then, a transformation module translates the JSON policies into fully compliant U-XACML policies. To ensure generality across different domains, we introduce a taxonomy-driven dataset creation, which enables policy creation for different environments such as smart homes, smart offices, and healthcare settings. Our evaluation demonstrates that the system achieves 93 % accuracy in policy generation and 91 % accuracy when handling ambiguous or noisy inputs. It also reaches 98 % agreement with expert-defined policies in real-world scenarios. Finally, on-device performance evaluations confirm the feasibility of running the model in practical settings, demonstrating reliable inference under constrained hardware conditions. Loay Alajramy, Marco Simoni, Marco Rasori, Andrea Saracino, Paolo Mori |
Future Gener. Comput. Syst. | 4 |
| 2026 | Concise thoughts: Impact of output length on LLM reasoning and cost
Sania Nayab, Giulio Rossolini, Marco Simoni, Andrea Saracino, Giorgio C. Buttazzo, Nicolamaria Manes, Fabrizio Giacomelli |
Inf. Sci. | 4 |
| 2025 | MATRIX: A Comprehensive Graph-Based Framework for Malware Analysis and Threat ResearchabstractThis paper presents MATRIX (Malware Analysis and Threat Research with STIX), a graph database for the comprehensive analysis and research of malware and threats. To provide a unified view of the threat landscape, MATRIX integrates data from major cybersecurity frameworks, including MITRE ATT&CK, DEF3ND, CAPEC, Malware Behavior Catalog (MBC), Metasploit, Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE). Developed in Neo4j using the Structured Threat Information Expression (STIXTM) standard, MATRIX includes more than 22,910 nodes and combines 14 STIX Domain Objects (SDOs) and 6 STIX Relationship Objects (SROs) to provide a detailed analysis of malware behavior, detection rules and defense strategies, making it a valuable tool for cybersecurity research. The system also integrates real-world malware reports and is automatically updated with data from sources such as VirusTotal, MalwareBazaar and VirusShare, supporting continuous and up-to-date threat analysis. We demonstrate its versatility through case studies comparing malware objectives and analyzing the impact of detection and mitigation. Marco Simoni, Andrea Saracino |
SECRYPT | 2 |
| 2025 | Trading-Off Privacy, Utility, and Explainability in Deep Learning-Based Image Data AnalysisabstractThis paper proposes a novel approach for multi-party collaborative data analysis problems, where analysis accuracy and divergence are required, as well as both privacy of shared data and explainability of results. The proposed approach aims at trading-off data privacy, decision explainability, and data utility by analytically relating these three measures, evaluating how they impact each other, and proposing a methodology to find the best possibletrade-offamong them. In particular, given a set of requirements from the participants for a collaborative analysis problem, we propose a method to properly tune the parameters of privacy-preserving mechanisms and explainability techniques to be adopted by all participants, obtaining the besttrade-off. The paper is focused on deep learning-based image data analysis problems, though the approach can be generalized to other data types. The$(\epsilon , \delta )$-Differential Privacyand theAutoencodersprivacy-preserving techniques have been adopted to preserve data privacy, while theSmoothGradmechanism has been used to provide decision explainability. The proposed methodology has been validated with a set of experiments on three multi-class deep learning classifiers and three well-known image datasets, MNIST, FER, and CIFAR-10. Wisam Abbasi, Paolo Mori, Andrea Saracino |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Further Insights: Balancing Privacy, Explainability, and Utility in Machine Learning-based Tabular Data AnalysisabstractIn this paper, we present further contributions to the field of privacy-preserving and explainable data analysis applied to tabular datasets. Our approach defines a comprehensive optimization criterion that balances the key aspects of data privacy, model explainability, and data utility. By carefully regulating the privacy parameter and exploring various configurations, our methodology identifies the optimal trade-off that maximizes privacy gain and explainability similarity while minimizing any adverse impact on data utility. To validate our approach, we conducted experiments using five classifiers on a binary classification problem using the well-known Adult dataset, which contains sensitive attributes. We employed (ϵ, δ)-differential privacy with generative adversarial networks as a privacy mechanism and incorporated various model explanation methods. The results showcase the capabilities of our approach in achieving the dual objectives of preserving data privacy and generating model explanations. Wisam Abbasi, Paolo Mori, Andrea Saracino |
ARES | 3 |
| 2024 | Cybersecurity with LLMs and RAGs: Challenges and Innovations
Marco Simoni, Andrea Saracino |
SecureComm (4) | 2 |
| 2023 | Graph-Based Android Malware Detection and Categorization through BERT TransformerabstractIn this paper, we propose a novel approach to Android malware analysis and categorization that leverages the power of BERT (Bidirectional Encoder Representations from Transformers) to classify API call sequences generated from Android API Call Graph. By utilizing the API Call Graph, our approach captures the intricate relationships and dependencies between API calls, enabling a deeper understanding of the behavior exhibited by Android malware. Our results show that our approach achieves high accuracy in classifying API call sequences as malicious or benign and the method provides a promising solution also for categorizing Android malware and can help mitigate the risks posed by malicious Android applications. Andrea Saracino, Marco Simoni |
ARES | 1 |
| 2023 | The Explainability-Privacy-Utility Trade-Off for Machine Learning-Based Tabular Data Analysis
Wisam Abbasi, Paolo Mori, Andrea Saracino |
SECRYPT | 3 |
| 2023 | Cyber threat intelligence for critical infrastructure securityabstractSummary Cyber‐attacks are considered the most significant threat to organizations from different sectors, including critical infrastructure. Access to critical assets, including industrial control systems, and control over their usage is one of the security approaches implemented to protect those systems from unauthorized access. However, existing implementations do not support the enforcement of fine‐grained authorization policies and do not provide continuous control over data access. Furthermore, existing implementations of the access control paradigm require policy‐makers to perform a manual update of policies that do not consider information about potential or ongoing cyber attacks. In this work, we propose a framework that enables continuous control on the execution of access rights in the industrial domain. Furthermore, the framework relies on cyber incident information shared by trusted entities. This information is used for updating security policies in order to prevent possible incidents within the smart factory infrastructure. We also provide experimental results that show the operability and the efficiency of the proposed framework. Oleksii Osliak, Andrea Saracino, Fabio Martinelli, Paolo Mori |
Concurr. Comput. Pract. Exp. | 2 |
| 2022 | Privacy vs Accuracy Trade-Off in Privacy Aware Face Recognition in Smart SystemsabstractThis paper proposes a novel approach for privacy preserving face recognition aimed to formally define a trade-off optimization criterion between data privacy and algorithm accuracy. In our methodology, real world face images are anonymized with Gaussian blurring for privacy preservation. The anonymized images are processed for face detection, face alignment, face representation, and face verification. The proposed methodology has been validated with a set of experiments on a well known dataset and three face recognition classifiers. The results demonstrate the effectiveness of our approach to correctly verify face images with different levels of privacy and results accuracy, and to maximize privacy with the least negative impact on face detection and face verification accuracy. Wisam Abbasi, Paolo Mori, Andrea Saracino, Valerio Frascolla |
ISCC | 3 |
| 2022 | Demo: Usage Control using Controlled Privacy Aware Face RecognitionabstractIn this paper, we demonstrate an application of privacy-preserving face recognition combined with an Attribute-Based Access Control framework to regulate access from subjects to critical resources while preserving the subject's privacy. The demonstrator exploits a mechanism that dynamically computes the best trade-off between ensured privacy and data utility, based on image acquisition conditions, and a decision engine based on XACML policies to express complex and dynamic conditions. The demonstrator can handle the dynamic association of new identities, as well as modification of access conditions. Attendees of the demo session can interact with the demo in a variety of ways, including modifying the camera input, but also through the customization of rules as well as the privacy parameter. Arpad Müller, Wisam Abbasi, Andrea Saracino |
ISCC | 3 |
| 2022 | Exploiting If This Then That and Usage Control obligations for Smart Home security and managementabstractSummary In this article we present an application of the Usage Control paradigm to a Smart Home infrastructure, based on a model extension and structured use of obligations. In the proposed extended model obligations are exploited to enforce two different access revocation time, namely revoke and suspend. This increases the policy expressiveness and enable to optimize the resource usage. Furthermore, obligations are exploited to send commands via IFTTT to different interconnected Smart Home devices, to impose safety‐relevant behaviors, or to act on policy attributes to implement a self‐healing paradigm for revoked sessions. The article is motivated by a parental control use case where deep learning is used in combination with Usage Control to regulate dynamically viewing rights of a smart‐TV and interactions with interconnected devices. Accuracy and performance experiments show the effectiveness and feasibility of the proposed work. Giacomo Giorgi, Antonio La Marra, Fabio Martinelli, Paolo Mori, Athanasios Rizos, Andrea Saracino |
Concurr. Comput. Pract. Exp. | 6 |
| 2021 | Towards Collaborative Cyber Threat Intelligence for Security Management
Oleksii Osliak, Andrea Saracino, Fabio Martinelli, Theodosis Dimitrakos |
ICISSP | 2 |
| 2021 | Using recurrent neural networks for continuous authentication through gait analysis
Giacomo Giorgi, Andrea Saracino, Fabio Martinelli |
Pattern Recognit. Lett. | 2 |
| 2021 | Ask a(n)droid to tell you the odds: probabilistic security-by-contract for mobile devices
Alessandro Aldini, Antonio La Marra, Fabio Martinelli, Andrea Saracino |
Soft Comput. | 4 |
| 2020 | Improving security in industry 4.0 by extending OPC-UA with usage controlabstractThis work presents a framework that provides ongoing control on actions execution in the industrial environment exploiting the OPC Unified Architecture (OPC-UA) framework and the Usage Control (UCON) paradigm. We present a fine-grained usage control model, referred as OPC-UCON, satisfying security and privacy needs of the OPC-UA framework. Our proposed framework exploits the OPC-UA connectivity between simulated industrial components and uses the UCON paradigm for dynamically controlling actions execution according to fine-grained policies reported in the standardized format. The UCON paradigm, in a form of the system, is in charge of controlling the process of dynamic policy reevaluation and the possibility of revoking already granted authorization by stopping previously authorized actions if conditions do not satisfy policy anymore. We presented the implementation and deployment of the proposed framework in a simulated industrial environment with relevant security policies to reflect the advantages of the OPC-UCON model. Fabio Martinelli, Oleksii Osliak, Paolo Mori, Andrea Saracino |
ARES | 4 |
| 2020 | Multi-level Distributed Intrusion Detection System for an IoT based Smart Home Environment
Simone Facchini, Giacomo Giorgi, Andrea Saracino, Gianluca Dini |
ICISSP | 3 |
| 2020 | Email Spoofing Attack Detection through an End to End Authorship Attribution System
Giacomo Giorgi, Andrea Saracino, Fabio Martinelli |
ICISSP | 2 |
| 2020 | Trust Aware Continuous Authorization for Zero Trust in Consumer Internet of ThingsabstractThis work describes the architecture and prototype implementation of a novel trust-aware continuous authorization technology that targets consumer Internet of Things (IoT), e.g., Smart Home. Our approach extends previous authorization models in three complementary ways: (1) By incorporating trust-level evaluation formulae as conditions inside authorization rules and policies, while supporting the evaluation of such policies through the fusion of an Attribute-Based Access Control (ABAC) authorization policy engine with a Trust-Level-Evaluation-Engine (TLEE). (2) By introducing contextualized, continuous monitoring and re-evaluation of policies throughout the authorization life-cycle. That is, mutable attributes about subjects, resources and environment as well as trust levels that are continuously monitored while obtaining an authorization, throughout the duration of or after revoking an existing authorization. Whenever change is detected, the corresponding authorization rules, including both access control rules and trust level expressions, are re-evaluated. (3) By minimizing the computational and memory footprint and maximizing concurrency and modular evaluation to improve performance while preserving the continuity of monitoring. Finally we introduce an application of such model in Zero Trust Architecture (ZTA) for consumer IoT. Theodosis Dimitrakos, Tezcan Dilshener, Alexander Kravtsov, Antonio La Marra, Fabio Martinelli, Athanasios Rizos, Alessandro Rosetti, Andrea Saracino |
TrustCom | 8 |
| 2019 | Enhancing Security in ETSI Open Source MANO with Usage Control Capability
Antonio La Marra, Alessio Lunardelli, Fabio Martinelli, Paolo Mori, Andrea Saracino, Piero Castoldi, Francesco Martino, Barbara Martini |
IM | 5 |
| 2019 | Using IFTTT to Express and Enforce UCON Obligations
Antonio La Marra, Fabio Martinelli, Paolo Mori, Athanasios Rizos, Andrea Saracino |
ISPEC | 5 |
| 2019 | Demonstration of secure slicing using ETSI MANO enhanced with Usage Control CapabilityabstractIn this demo we show the functionalities of the Open Source MANO extended with advanced authorization capabilities able to enhance the security support in terms of preservation of virtual resources and slices integrity in a dynamic context of users, services and resources. The presented extension consists of a Usage Control System integrated with Open Source MANO enhancing traditional authorization operations with ongoing usage control on established slices, virtual resources and user behaviour by continuously reconsidering the granting of resources in light of mutable attribute of users, resources and environment (e.g., presence of viruses, set-up of weak passwords). Antonio La Marra, Alessio Lunardelli, Fabio Martinelli, Paolo Mori, Andrea Saracino, Piero Castoldi, Francesco Marino 0002, Barbara Martini |
NetSoft | 5 |
| 2019 | Obligation Management in Usage Control SystemsabstractModern decentralized and distributed environments, as typical from IoT or Industry 4.0 architectures, require a more advanced and granular security management than the currently available standard access control methodologies. Obligations, as defined by the Usage Control model, have been introduced to enhance the traditional access control security mechanisms by imposing the execution of policy-determined actions. This paper presents an extension of the architecture of the Usage Control system already existing in literature, which aims at formalizing the management of Obligations. Three additional components, naturally integrated within the Usage Control system, verify and/or ensure the correct enforcement of obligations also allowing their effect to be evaluated in the continuous access decision making process. The proposed extension thus allows to verify complex conditions when evaluating obligation- specific attributes extracted from the domain where obligations are enforced or observed. Fabio Martinelli, Paolo Mori, Andrea Saracino, Francesco Di Cerbo |
PDP | 3 |
| 2019 | A scheme for the sticky policy representation supporting secure cyber-threat intelligence analysis and sharingabstractPurpose This paper aims to propose a structured threat information expression (STIX)-based data representation for privacy-preserving data analysis to report format and semantics of specific data types and to represent sticky policies in the format of embedded human-readable data sharing agreements (DSAs). More specifically, the authors exploit and extend the STIX standard to represent in a structured way analysis-ready pieces of data and the attached privacy policies. Design/methodology/approach The whole scheme is designed to be completely compatible with the STIX 2.0 standard for cyber-threat intelligence (CTI) representation. The proposed scheme will be implemented in this work by defining the complete scheme for representing an email, which is more expressive than the standard one defined for STIX, designed specifically for spam email analysis. Findings Moreover, the paper provides a new scheme for general DSA representation that has been practically applied for the process of encoding specific attributes in different CTI reports. Research limitations/implications Because of the chosen approach, the research results may have limitations. Specifically, current practice for entity recognition has the limitation that was discovered during the research. However, its effect on process time was minimized and the way for improvement was proposed. Originality/value This paper has covered the existing gap including the lack of generality in DSA representation for privacy-preserving analysis of structured CTI. Therefore, the new model for DSA representation was introduced, as well as its practical implementation. Oleksii Osliak, Andrea Saracino, Fabio Martinelli |
Inf. Comput. Secur. | 2 |
| 2018 | POSTER: A Framework for Phylogenetic Analysis in Mobile EnvironmentabstractTo maximize the probability of successful attacks and reduce the odds of being detected, malware developers implement different versions of the same malicious payloads. As a matter of fact, malware writers often generate new malicious code starting from existing ones, adding small programmed variations, or applying obfuscation mechanisms, that change the code structure, without altering the malicious functionalities. For these reasons phylogenetic analysis is becoming of interest as instrument for malware analysts in order to understand the derivation of a malicious payload, being thus able to reconduct a derived piece of code to its original, known originator. In this poster we describe a framework designed to infer and shape the phylogenetic tree of mobile malicious applications. The framework considers multi-level features with rule-based machine learning algorithm to retrieve antecedents and descendants of malicious samples. Fabio Martinelli, Francesco Mercaldo, Andrea Saracino |
AsiaCCS | 3 |
| 2018 | Not so Crisp, Malware! Fuzzy Classification of Android Malware ClassesabstractMobile devices have been spreading at great rate in recent years. Not only smartphone, but also tablets and IoT devices, are gaining an increasingly place in our everyday lives. This is the reason why attackers are developing more and more aggressive techniques with the aim to exfiltrate our sensitive and private information. As many studies demonstrate, mobile malware is not developed from the scratch, as a matter of fact new malware samples are usually generated by adding new functionalities to existing malicious payloads, in order to make it more aggressive and undetectable by current antimalware technologies. As result of this process, current mobile malware exhibits several behaviors merged belonging to different malicious families. Considering this nature of the mobile malicious payloads, in this paper we explore whether fuzzy logic is helpful to (i) classify malicious applications into a set of classes we defined and, (ii) identify whether an application under analysis exhibits behaviors belonging to different malware classes we defined. Results are encouraging, as a matter of fact we obtain a weight precision and a recall equal to 0.975 in malware class identification on a dataset of 5332 real-world Android malware, and we demonstrate that the proposed method is able to identify the several malicious behaviors in terms of percentage of the samples under analysis. Francesco Mercaldo, Andrea Saracino |
FUZZ-IEEE | 2 |
| 2018 | Walking Through the Deep: Gait Analysis for User Authentication Through Deep Learning
Giacomo Giorgi, Fabio Martinelli, Andrea Saracino, Mina Alishahi |
SEC | 3 |
| 2018 | Privacy Preserving Distributed Computation of Private Attributes for Collaborative Privacy Aware Usage Control SystemsabstractCollaborative smart services provide functionalities which exploit data collected from different sources to provide benefits to a community of users. Such data, however, might be privacy sensitive and their disclosure has to be avoided. In this paper, we present a distributed multi-tier framework intended for smart-environment management, based on usage control for policy evaluation and enforcement on devices belonging to different collaborating entities. The proposed framework exploits secure multi-party computation to evaluate policy conditions without disclosing actual value of evaluated attributes, to preserve privacy. As reference example, a smart-grid use case is presented. Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Paolo Mori, Andrea Saracino |
SMARTCOMP | 5 |
| 2018 | Risk analysis of Android applications: A user-centric solution
Gianluca Dini, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi, Andrea Saracino, Daniele Sgandurra |
Future Gener. Comput. Syst. | 5 |
| 2018 | MADAM: Effective and Efficient Behavior-based Android Malware Detection and PreventionabstractAndroid users are constantly threatened by an increasing number of malicious applications (apps), generically called malware. Malware constitutes a serious threat to user privacy, money, device and file integrity. In this paper we note that, by studying their actions, we can classify malware into a small number of behavioral classes, each of which performs a limited set of misbehaviors that characterize them. These misbehaviors can be defined by monitoring features belonging to different Android levels. In this paper we present MADAM, a novel host-based malware detection system for Android devices which simultaneously analyzes and correlates features at four levels: kernel, application, user and package, to detect and stop malicious behaviors. MADAM has been specifically designed to take into account those behaviors that are characteristics of almost every real malware which can be found in the wild. MADAM detects and effectively blocks more than 96 percent of malicious apps, which come from three large datasets with about 2,800 apps, by exploiting the cooperation of two parallel classifiers and a behavioral signature-based detector. Extensive experiments, which also includes the analysis of a testbed of 9,804 genuine apps, have been conducted to show the low false alarm rate, the negligible performance overhead and limited battery consumption. Andrea Saracino, Daniele Sgandurra, Gianluca Dini, Fabio Martinelli |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | BRIDEMAID: An Hybrid Tool for Accurate Detection of Android MalwareabstractThis paper presents BRIDEMAID, a framework which exploits an approach static and dynamic for accurate detection of Android malware. The static analysis is based on n-grams matching, whilst the dynamic analysis is based on multi-level monitoring of device, app and user behavior. The framework has been tested against 2794 malicious apps reporting a detection accuracy of 99,7% and a negligible false positive rate, tested on a set of 10k genuine apps. Fabio Martinelli, Francesco Mercaldo, Andrea Saracino |
AsiaCCS | 3 |
| 2017 | Privacy-preserving text mining as a serviceabstractText mining is the process to automatically infer relevant information from semantically related text documents. This technique, which has applications from business intelligence to homeland security, terrorism and crime fight, might bring noticeable privacy issues when analyzed documents contain privacy sensitive information. In this paper, we propose a framework for privacy-preserving text analysis, which exploits Homomorphic Encryption, to analyze text documents in a privacy preserving manner. The proposed framework is designed to ensure that there is no disclosure of privacy sensitive information contained in the document to any party, including the analysis engine itself. Furthermore, we present two use cases of analysis based on bag-of-words classification, where the proposed framework manages to obtain good classification results without information disclosure. In particular the two different settings that are considered are: tweet analysis for detection of terrorist Twitter accounts, and out-box email analysis for detection of bot infected devices. Accuracy results with different classifiers, performances and a security analysis of our approach are presented and discussed. Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Andrea Saracino, Mina Alishahi |
ISCC | 4 |
| 2017 | Concurrent History-based Usage Control Policies
Fabio Martinelli, Ilaria Matteucci, Paolo Mori, Andrea Saracino |
MODELSWARD | 4 |
| 2017 | A Distributed Framework for Collaborative and Dynamic Analysis of Android MalwareabstractCombination of dynamic and static analysis is very effective in detecting malicious Android apps. However, dynamic analysis is hardly practiced on large scale, due to the necessary active interaction with the malicious app, which is reliable only if performed by a user on a real device. In this paper we present a framework for distributed and collaborative analysis of Android suspicious apps, which leverages real users to test the functionality of apps and detect eventual malicious behaviors by exploiting an on-host app for intrusion detection. The paper introduces the architecture, workflow and protocols to handle the report received by participating users, detecting and filtering the malicious ones. Simulative results to assess the performance of the proposed framework are reported and discussed. Mario Faiella, Antonio La Marra, Fabio Martinelli, Francesco Mercaldo, Andrea Saracino, Mina Alishahi |
PDP | 5 |
| 2016 | Collaborative Attribute Retrieval in Environment with Faulty Attribute ManagersabstractAttributes describing the features of subjects, objects and of the environment are used in access and usage control models to determine the right of a subject to use an object in a given environment. Hence, it is crucial for the effective enforcement of access and usage policies that authorization systems are able to promptly retrieve the values of the required attributes from the Attribute Providers. However, sometimes attribute providers could not respond when queried by Authorization systems, because they could be temporary down or unreachable. This could affect the decision processes, causing some requests to be unduly denied or some ongoing accesses to be unduly interrupted. This paper proposes a strategy that can be adopted by an Authorization system to estimate the value of the attributes it requires when the corresponding attribute providers are not responding. This strategy leverages on the collaboration of the other Authorization systems which exploit the same attribute providers, and which could have cached a value for the required attributes. We validate the presented approach through a set of simulative experiments which consider the presence of malicious authorization systems in the cooperative environment. Mario Faiella, Fabio Martinelli, Paolo Mori, Andrea Saracino, Mina Alishahi |
ARES | 4 |
| 2016 | Data-Sluice: Fine-grained traffic control for Android applicationabstractAndroid applications (apps) generate a consistent amount of data traffic. A noticeable share of this generated data traffic is used to convey third party advertisement, or to collect information about the user and its phone, generally with the target of profiling users. Such a traffic is not needed to the correct app execution and can be considered unwanted overhead. In this paper we propose Data-Sluice, a framework for Android devices which dynamically controls the connections opened by apps, enforcing fine grained policies designed to stop advertisement from altering the user experience, avoiding private data leakage and removing or strongly reducing the data traffic overhead. We apply Data-Sluice to a set of popular Android apps to analyze the generated traffic and removing the data overhead. Furthermore, we exploit Data-Sluice to successfully stop the action of a set of malicious apps. Andrea Saracino, Fabio Martinelli, Gaetano Alboreto, Gianluca Dini |
ISCC | 1 |
| 2016 | I find your behavior disturbing: Static and dynamic app behavioral analysis for detection of Android malwareabstractMalicious Android applications are currently the biggest threat in the scope of mobile security. To cope with their exponential growth and with their deceptive and hideous behaviors, static analysis signature based approaches are not enough to timely detect and tackle brand new threats such as polymorphic and composition malware. This work presents BRIDEMAID, a novel framework for analysis of Android apps' behavior, which exploits both a static and dynamic approach to detect malicious apps directly on mobile devices. The static analysis is based on n-grams matching to statically recognize malicious app execution patterns. The dynamic analysis is instead based on multi-level monitoring of device, app and user behavior to detect and prevent at runtime malicious behaviors. The framework has been tested against 2794 malicious apps reporting a detection accuracy of 99,7% and a negligible false positive rate, tested on a set of 10k genuine apps. Fabio Martinelli, Francesco Mercaldo, Andrea Saracino, Corrado Aaron Visaggio |
PST | 3 |
| 2016 | LVS: A WiFi-based system to tackle Location Spoofing in location-based servicesabstractThe reliability of location-based services (LBS) is strongly dependent on the accuracy of the location of the users. However, existing LBS systems are not able to efficiently validate the position of users in large-scale outdoor environments, leading to possible location spoofing attacks by malicious users. To this end, we present an efficient and scalable Location Validation System (LVS) that secures LBS systems from location spoofing attacks. In particular, the user location is verified with the help of mobile WiFi hotspots (MHSs), who are users activating the WiFi hotspot capability of their smartphones and accept connections from nearby users, thereby validating their position inside the sensing area. The system also comprises a novel verification technique called Chains of Sight, which tackles collusion-based attacks effectively. LVS also includes a reputation-based algorithm that rules out sensing reports of location-spoofing users. Francesco Restuccia 0001, Andrea Saracino, Sajal K. Das 0001, Fabio Martinelli |
WoWMoM | 2 |
| 2015 | Detection of repackaged mobile applications through a collaborative approachabstractSummary Repackaged applications are based on genuine applications, but they subtlety include some modifications. In particular, trojanized applications are one of the most dangerous threats for smartphones. Malware code may be hidden inside applications to access private data or to leak user credit. In this paper, we propose a contract‐based approach to detect such repackaged applications, where a contract specifies the set of legal actions that can be performed by an application. Current methods to generate contracts lack information from real usage scenarios, thus being inaccurate and too coarse‐grained. This may result either in generating too many false positives or in missing misbehaviors when verifying the compliance between the application and the contract. In the proposed framework, application contracts are generated dynamically by a central server merging execution traces collected and shared continuously by collaborative users executing the application. More precisely, quantitative information extracted from execution traces is used to define a contract describing the expected application behavior, which is deployed to the cooperating users. Then, every user can use the received contract to check whether the related application is either genuine or repackaged. Such a verification is based on an enforcement mechanism that monitors the application execution at run‐time and compares it against the contract through statistical tests. Copyright © 2014 John Wiley & Sons, Ltd. Alessandro Aldini, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
Concurr. Comput. Pract. Exp. | 3 |
| 2013 | Probabilistic Contract Compliance for Mobile ApplicationsabstractWe propose PICARD (ProbabIlistic Contract on Android), a framework to generate probabilistic contracts to detect repackaged applications for Android smart phones. A contract describes the sequences of actions that an application is allowed to perform at run-time, i.e. its legal behavior. In PICARD, contracts are generated from the set of traces that represent the usage profile of the application. Both the contract and the application's run-time behavior are represented through clustered probabilistic automata. At run-time, the PICARD monitoring system verifies the compliance of the application trace with the contract. This approach is useful in detecting repackaged applications, whose behavior is strongly similar to the original application but it differs only from small paths in the traces. In this paper, we discuss the framework of PICARD for describing and generating contracts through probabilistic automata and introduce the notion of Action Node, a cluster of related system calls, used to represent high level operations. Then, we present a first set of preliminary experiments on repackaged applications, to evaluate the viability of the proposed approach. Gianluca Dini, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
ARES | 3 |
| 2013 | Towards enforcing on-the-fly policies in BYOD environmentsabstractThe Bring Your Own Device (BYOD) paradigm is becoming extremely popular across all kind of organizations. In fact, employees are continually trying to incorporate their personal devices, e.g. smartphones and tablets, into the office to perform some of their work or simply to access the Internet with a device they trust or they are more familiar with. Unfortunately, several security issues may arise from all these external devices accessing the corporate network. To address these issues, in this paper we propose a framework that enforces on-the-fly instantiated policies inside organizations using trusted BYOD technologies. The proposed framework implements a role-based access control system based upon user identity and her current context. To this end, each user receives a specific policy from a server based upon the current role and context. The effective user identity is confirmed using OAuth 2.0, while the device integrity and policy enforcement is ensured by means of a on-device root-of-trust and an enforcer running on each device. Gianpiero Costantino, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
IAS | 3 |