Enrico Cambiaso

dblp:121/3854 · DBLP profile ↗
← Back
14ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-6932-1975ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 2 since 2021Computer networks · 3 · 1 first-authorArtificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Seeing the invisible: Detection of stealth DoS attacks using variational U-Net-like models
abstract
The increasing sophistication of cyberattacks targeting companies and organizations continues to challenge the effectiveness of modern defense systems. Among these threats, slow Denial-of-Service (slow DoS) attacks are particularly difficult to detect, as they rely on evasion strategies that add significant complexity to cybersecurity efforts. Modern intrusion detection systems, especially those based on deep learning, have become essential tools in combating such attacks. However, their performance is often hindered by challenges such as limited data availability, noisy inputs, and the presence of out-of-distribution samples. Furthermore, their dependence on large labeled datasets makes detecting subtle or rare attack patterns particularly challenging. To overcome these limitations, this work proposes a novel unsupervised deep learning framework for detecting slow DoS attacks. The proposed approach incorporates a customized preprocessing pipeline to improve input data quality and leverages a sparse variational U-Net-like architecture for robust anomaly identification. Extensive experiments conducted on three real-world datasets demonstrate the ability of the framework to accurately and efficiently detect slow DoS attacks, highlighting its robustness, generalizability, and practical suitability for deployment in operational environments.
Enrico Cambiaso, Francesco Folino, Massimo Guarascio 0001, Angelica Liguori, Antonino Rullo
J. Inf. Secur. Appl.1
2025 Explainable evaluation of generative adversarial networks for wearables data augmentation
abstract
Data augmentation represents an opportunity for Artificial Intelligence (AI) applications, as it aims at creating new synthetic data based on an existing baseline. In this paper, we present a new evaluation framework for Generative Adversarial Networks (GANs), a data augmentation technique, in multivariate data classification contexts. The goal is not limited to assessing the performance variations obtained through GANs, but also to inspect results with explainable AI (XAI) tools, understanding how GANs work and, finally, exploiting them to discover new knowledge. To this aim, we adopt the Logic Learning Machine (LLM) for performance assessment and rule extraction, and introduce a new measure of rule similarity to compare different artificial datasets. We apply the methodology on two case studies , activity recognition and physical fatigue detection, confirming that GANs can help in overcoming limitations of original datasets and lead to new discoveries.
Sara Narteni, Vanessa Orani, Enrico Ferrari, Damiano Verda, Enrico Cambiaso, Maurizio Mongelli
Eng. Appl. Artif. Intell.5
2023 Information Leakages of Docker Containers: Characterization and Mitigation Strategies
abstract
Compared to classic virtual machines, containers offer lightweight and dynamic execution environments. Hence, they are core building blocks for the development of future softwarized networks and cloud-native applications. However, containers still pose many security challenges, which are less understood compared to other virtualization paradigms. An important aspect often neglected concerns techniques enabling containers to leak data outside their execution perimeters, e.g., to exfiltrate sensitive information or coordinate attacks. In this paper we investigate security impacts of covert communications based on the looser isolation of memory statistics information. Our characterization indicates that the investigation of system calls should be considered a prime tool to reveal the presence of collusive attack schemes. We also elaborate on two mitigation techniques: the first entails prevention via “hardening” configurations of containers, while the second implements a run-time disruption mechanism.
Marco Zuppelli, Matteo Repetto, Luca Caviglione, Enrico Cambiaso
NetSoft4
2022 A New XAI-based Evaluation of Generative Adversarial Networks for IMU Data Augmentation
abstract
Data augmentation is a widespread innovative technique in Artificial Intelligence: it aims at creating new synthetic data given an existing real baseline, thus allowing to overcome the issues arising from the lack of labelled data for proper training of classification algorithms. Our paper focuses on how a common data augmentation methodology, the Generative Adversarial Networks (GANs), which is widespread for images and timeseries data, can be also applied to generate multivariate data. We propose a novel scheme for GANs evaluation, based on the performance of an explainable AI (XAI) algorithm and an innovative definition of rule similarity. In particular, we will consider an application dealing with the augmentation of Inertial Movement Units (IMU) data for physical fatigue monitoring in two age subgroups (under and over 40 years old) of the original data. We will show how our innovative rule similarity metric can drive the selection of the best fake dataset among a set of different candidates, corresponding to different GAN training runs.
Sara Narteni, Vanessa Orani, Enrico Ferrari, Damiano Verda, Enrico Cambiaso, Maurizio Mongelli
HealthCom5
2021 DoS Attacks in Available MQTT Implementations: Investigating the Impact on Brokers and Devices, and supported Anti-DoS Protections
abstract
The Internet of Things is a widely adopted and pervasive technology, but also one of the most conveniently attacked given the volume of shared data and the availability of affordable but insecure products. This paper investigates two classes of denial of service (DoS) attacks that target the handling of message queues in MQTT, one of the most broadly used IoT protocols. The first attack attempts to saturate the MQTT broker resources, while the second exploits the broker to perform an amplification attack against the connected clients. We demonstrate the effectiveness of the attacks and indicate the parameters that would hinder the capabilities of a DoS attacker in three open-source MQTT implementations: Mosquitto, VerneMQ and EMQ X. To improve the security awareness in MQTT-based deployments, we integrate the attacks and mitigations in MQTTSA, a tool that detects MQTT misconfigurations and provides security-oriented recommendations and configuration snippets.
Umberto Morelli, Ivan Vaccari, Silvio Ranise, Enrico Cambiaso
ARES4
2021 From Explainable to Reliable Artificial Intelligence
Sara Narteni, Melissa Ferretti, Vanessa Orani, Ivan Vaccari, Enrico Cambiaso, Maurizio Mongelli
CD-MAKE5
2020 Detection and classification of slow DoS attacks targeting network servers
abstract
Low-rate denial of service attacks are considered a serious threat for network systems. In this paper, we investigate such topic, by proposing a novel anomaly-based intrusion detection system. We validate the proposed system and report the weaknesses we have found. By working from the attacker's perspective, we also try to elude the proposed algorithm. Results show that in order to avoid detection, the attacker would require high-bandwidth to perpetrate the attack. The proposed method should therefore be considered an efficient method to detect running Slow DoS Attacks.
Enrico Cambiaso, Maurizio Aiello, Maurizio Mongelli, Ivan Vaccari
ARES1
2020 Challenges and Opportunities of IoT and AI in Pneumology
abstract
The objective of this work is the design of a technological platform for remote monitoring of patients with Chronic Obstructive Pulmonary Disease (COPD). The concept of the framework is a breakthrough in the state of medical, scientific and technological art, aimed at engaging patients in the treatment plan and supporting interaction with healthcare professionals. The proposed platform is able to support a new paradigm for the management of patients with COPD, by integrating clinical data and parameters monitored in daily life using Artificial Intelligence algorithms. Therefore, the doctor is provided with a dynamic picture of the disease and its impact on lifestyle and vice versa, and can thus plan more personalized diagnostics, therapeutics, and social interventions. This strategy allows for a more effective organization of access to outpatient care and therefore a reduction of emergencies and hospitalizations because exacerbations of the disease can be better prevented and monitored. Hence, it can result in improvements in patients' quality of life and lower costs for the healthcare system.
Maurizio Mongelli, Vanessa Orani, Enrico Cambiaso, Ivan Vaccari, Alessia Paglialonga, Fulvio Braido, Chiara Eva Catalano
DSD3
2019 Introducing the SlowDrop Attack
abstract
In network security, Denial of Service (DoS) attacks target network systems with the aim of making them unreachable. Last generation threats are particularly dangerous because they can be carried out with very low resource consumption by the attacker. In this paper we propose SlowDrop, an attack characterized by a legitimate-like behavior and able to target different protocols and server systems. The proposed attack is the first slow DoS threat targeting Microsoft IIS, until now unexploited from other similar attacks. We properly describe the attack, analyzing its ability to target arbitrary systems on different scenarios, by including both wired and wireless connections, and comparing the proposed attack to similar threats. The obtained results show that by executing targeted attacks, SlowDrop is successful both against conventional servers and Microsoft IIS, which is closed source and required us the execution of so called “network level reverse engineering” activities. Due to its ability to successfully target different servers on different scenarios, the attack should be considered an important achievement in the slow DoS field.
Enrico Cambiaso, Giovanni Chiola, Maurizio Aiello
Comput. Networks1
2017 Slowcomm: Design, development and performance evaluation of a new slow DoS attack
Enrico Cambiaso, Gianluca Papaleo, Maurizio Aiello
J. Inf. Secur. Appl.1
2017 Remotely Exploiting AT Command Attacks on ZigBee Networks
abstract
Internet of Things networks represent an emerging phenomenon bringing connectivity to common sensors. Due to the limited capabilities and to the sensitive nature of the devices, security assumes a crucial and primary role. In this paper, we report an innovative and extremely dangerous threat targeting IoT networks. The attack is based on Remote AT Commands exploitation, providing a malicious user with the possibility of reconfiguring or disconnecting IoT sensors from the network. We present the proposed attack and evaluate its efficiency by executing tests on a real IoT network. Results demonstrate how the threat can be successfully executed and how it is able to focus on the targeted nodes, without affecting other nodes of the network.
Ivan Vaccari, Enrico Cambiaso, Maurizio Aiello
Secur. Commun. Networks2
2016 Are mobile botnets a possible threat? The case of SlowBot Net
Paolo Farina, Enrico Cambiaso, Gianluca Papaleo, Maurizio Aiello
Comput. Secur.2
2015 Detection of DoS attacks through Fourier transform and mutual information
abstract
Due to their recent appearance and the reduced requirements in terms of network bandwidth, Slow Denial of Service Attacks detection represents a particularly challenging problem. This paper presents a novel detection method, analyzing spectral features of the network traffic over small time horizons. The proposed method has been validated by extrapolating data referred to real traffic traces, elaborated over the Local Area Network of our research institute. We have considered different kinds of attacks and results show how the proposed approach is reliable and applicable also in other cybersecurity contexts.
Maurizio Mongelli, Maurizio Aiello, Enrico Cambiaso, Gianluca Papaleo
ICC3
2013 A similarity based approach for application DoS attacks detection
abstract
The ability to identify anomalous traffic patterns is a central issue for network managers: primarily lots of problems could arise from network attacks, such as viruses and tunneling tools. In this paper we present a detection algorithm able to extract information analyzing features of the network traffic containing attacks. The algorithm exploits statistical methodologies for traffic categorization. To assess the practical usability of the proposed algorithms we have tested its application in a case of abuse of resources through an application DoS attack known as slowloris. We have obtained an excellent reliability both analyzing single samples of traffic (100% of anomalies detection, with 1% probability of false positives) and processing multiple samples, through an average measurement (100% of anomalies detection, with a distance between traffics of 5.29 σ, providing an extremely low false positive error rate).
Maurizio Aiello, Enrico Cambiaso, Silvia Scaglione, Gianluca Papaleo
ISCC2