Danilo Bruschi

dblp:14/3451 · DBLP profile ↗
← Back
47ranked-venue papers
24as first author
5since 2021 · last 2026
0000-0002-5905-5976ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 12 first-author · 5 since 2021Theory of computation · 9 · 6 first-authorSoftware engineering, systems software and programming languages · 7 · 3 first-authorComputer networks · 6 · 3 first-authorSystems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 RemOTA: Remote attestation for detecting use-after-free in low-power microcontrollers
abstract
In this paper, we introduce RemOTA , a novel remote attestation protocol to capture dynamic memory allocations and uses in microcontroller embedded systems, enabling detection of use-after-free errors. RemOTA performs a precomputation analysis to identify a minimal set of key points in the control flow graph, called checkpoints, which serve as boundaries enclosing sequences of pointer operations that occur along the same execution path. These checkpoints allow the grouping of multiple pointer usages into larger, semantically meaningful units, enabling efficient and targeted instrumentation. This approach is particularly effective in resource-constrained environments, as it minimizes runtime overhead while offloading verification to a remote server. RemOTA incorporates a remote verifier that receives information from the executing firmware and replicates instructions to dynamically reconstruct pointer usage and emulate memory state, allowing lightweight use-after-free detection. Through the evaluation of real-world firmware on an STM32 microcontroller, RemOTA demonstrates high precision 100% with low overhead, geometric mean 4.47% on the tested dataset. Its scalability and efficiency make RemOTA a practical solution for securing resource-constrained embedded devices in production environments.
Matteo Zoia, Mirco Picca, Davide Rusconi, Andrea Monzani, Flavio Toffalini, Danilo Bruschi, Andrea Lanzi
Comput. Secur.6
2025 VS-TEE: A Framework for Virtualizing TEEs in ARM Cloud Contexts
abstract
Cloud computing processes and stores critical data, necessitating robust protections against unauthorized access. Confidential Computing (CC) technologies address this need by enabling secure computation in hardware-backed Trusted Execution Environments (TEEs). While solutions like AMD's Secure Encrypted Virtualization (SEV) provide strong protections, they remain vulnerable to attacks targeting applications within virtual machines (VMs). Similarly, the recent Armv9-A architecture introduces a promising Realm World for enhanced security, but its adoption is limited by hardware availability and upgrade constraints. ARM TrustZone, while widely supported, lacks native support for multiple isolated TEEs. In this paper we proposed framework eliminates the need for these components in the Trusted Computing Base (TCB), enabling secure integration of TEEs with VMs. It features a VS-TEE Driver for VM interaction and a VS-TEE Hypervisor for secure communication, ensuring compatibility with ARM TrustZone and OP-TEE libraries. We developed and evaluated an open-source prototype, demonstrating its effectiveness in addressing challenges like memory translation, resource management, and interoperability. Our framework enhances security for cloud environments, allowing multiple VMs to securely share TEE capabilities.
Matteo Zoia, Marco Cutecchia, Davide Rusconi, Andrea Monzani, Mirco Picca, Danilo Bruschi, Andrea Lanzi
CODASPY6
2024 Ensuring cybersecurity for industrial networks: A solution for ARP-based MITM attacks
abstract
The increased adoption of the Internet Protocol (IP) in ICSs has made these systems vulnerable to the same security risks that are present in traditional IT environments. The legacy nature of ICSs and their unique operational requirements make them vulnerable to security threats that are different from those in IT environments. In this paper, we describe a protocol, named ArpON, which is able to wipe out in quasi real time any ARP cache poisoning attempt, thus making it ineffective. Contrarily to solutions presented in the literature for contrasting ARP cache poisoning, ArpON incurs in low operational costs, is backward compatible, transparent to the ARP protocol and does not use any HW feature nor cryptography functionality. We also model and validate ArpON in the OMNET[Formula: see text] network simulator. The simulation results show that ArpON is effective in avoiding ARP poisoning, and its communication overhead is negligible with respect to classical ARP protocol.
Danilo Bruschi, Andrea Di Pasquale, Andrea Lanzi, Elena Pagani
J. Comput. Secur.1
2022 A Formal Verification of ArpON - A Tool for Avoiding Man-in-the-Middle Attacks in Ethernet Networks
abstract
Since the nineties, the Man-in-The-Middle (MITM) attack has been one of the most effective strategies adopted for compromising information security in network environments. In this article, we focus our attention on ARP cache poisoning, which is one of the most well-known and more adopted techniques for performing MITM attacks in Ethernet local area networks. More precisely, we will prove that, in network environments with at least one malicious host in the absence of cryptography, an ARP cache poisoning attack cannot be avoided. Subsequently, we advance ArpON, an efficient and effective solution to counteract ARP cache poisoning, and we use a model-checker for verifying its safety property. Our main finding, in accordance with the above impossibility result, is that the only event that compromises the safety of ArpON is a cache poisoning that nevertheless is removed by ArpON itself after a very short period, thus making it practically infeasible to perpetrate an ARP cache poisoning attack on network hosts where ArpON is installed.
Danilo Bruschi, Andrea Di Pasquale, Silvio Ghilardi, Andrea Lanzi, Elena Pagani
IEEE Trans. Dependable Secur. Comput.1
2021 Glyph: Efficient ML-Based Detection of Heap Spraying Attacks
abstract
Heap spraying is probably the most simple and effective memory corruption attack, which fills the memory with malicious payloads and then jumps at a random location in hopes of starting the attacker's routines. To counter this threat, GRAFFITI has been recently proposed as the first OS-agnostic framework for monitoring memory allocations of arbitrary applications at runtime; however, the main contributions of GRAFFITI are on the monitoring system, and its detection engine only considers simple heuristics which are tailored to certain attack vectors and are easily evaded. In this article, we aim to overcome this limitation and propose GLYPH as the first ML-based heap spraying detection system, which is designed to be effective, efficient, and resilient to evasive attackers. GLYPH relies on the information monitored by GRAFFITI, and we investigate the effectiveness of different feature spaces based on information entropy and memory n-grams, and discuss the several engineering challenges we have faced to make GLYPH efficient with an overhead compatible with that of GRAFFITI. To evaluate GLYPH, we build a representative dataset with several variants of heap spraying attacks, and assess GLYPH's resilience against evasive attackers through selective hold-out experiments. Results show that GLYPH achieves high accuracy in detecting spraying and is able to generalize well, outperforming the state-of-the-art approach for heap spraying detection, NOZZLE. Finally, we thoroughly discuss the trade-offs between detection performance and runtime overhead of GLYPH's different configurations.
Fabio Pierazzi, Stefano Cristalli, Danilo Bruschi, Michele Colajanni, Mirco Marchetti, Andrea Lanzi
IEEE Trans. Inf. Forensics Secur.3
2019 Detecting (absent) app-to-app authentication on cross-device short-distance channels
abstract
Short-distance or near-field communication is increasingly used by mobile apps for interacting or exchanging data in a cross-device fashion. In this paper, we identify a security issue, namely cross-device app-to-app communication hijacking (or CATCH), that affect Android apps using short-distance channels (e.g., Bluetooth and Wi-Fi-Direct). This issue causes unauthenticated or malicious app-to-app interactions even when the underlying communication channels are authenticated and secured. In addition to discovering the security issue, we design an algorithm based on data-flow analysis for detecting the presence of CATCH in Android apps. Our algorithm checks if a given app contains an app-to-app authentication scheme, necessary for preventing CATCH. We perform experiments on a set of Android apps and show the CATCH problem is always present on the whole analyzed applications set. We also discuss the impact of the problem in real scenarios by presenting two real case studies. At the end of the paper we reported limitations of our model along with future improvements.
Stefano Cristalli, Long Lu, Danilo Bruschi, Andrea Lanzi
ACSAC3
2019 BootKeeper: Validating Software Integrity Properties on Boot Firmware Images
abstract
Boot firmware, like UEFI-compliant firmware, has been the target of numerous attacks, giving the attacker control over the entire system while being undetected. The measured boot mechanism of a computer platform ensures its integrity by using cryptographic measurements to detect such attacks. This is typically performed by relying on a Trusted Platform Module (TPM). Recent work, however, shows that vendors do not respect the specifications that have been devised to ensure the integrity of the firmware's loading process. As a result, attackers may bypass such measurement mechanisms and successfully load a modified firmware image while remaining unnoticed. In this paper we introduce BootKeeper, a static analysis approach verifying a set of key security properties on boot firmware images before deployment, to ensure the integrity of the measured boot process. We evaluate BootKeeper against several attacks on common boot firmware implementations and demonstrate its applicability.
Ronny Chevalier, Stefano Cristalli, Christophe Hauser, Yan Shoshitaishvili, Ruoyu Wang 0001, Christopher Krügel, Giovanni Vigna, Danilo Bruschi, Andrea Lanzi
CODASPY8
2018 Trusted Execution Path for Protecting Java Applications Against Deserialization of Untrusted Data
Stefano Cristalli, Edoardo Vignati, Danilo Bruschi, Andrea Lanzi
RAID3
2017 Formal Verification of ARP (Address Resolution Protocol) Through SMT-Based Model Checking - A Case Study -
Danilo Bruschi, Andrea Di Pasquale, Silvio Ghilardi, Andrea Lanzi, Elena Pagani
IFM1
2013 A methodology for testing CPU emulators
abstract
A CPU emulator is a software system that simulates a hardware CPU. Emulators are widely used by computer scientists for various kind of activities (e.g., debugging, profiling, and malware analysis). Although no theoretical limitation prevents developing an emulator that faithfully emulates a physical CPU, writing a fully featured emulator is a very challenging and error prone task. Modern CISC architectures have a very rich instruction set, some instructions lack proper specifications, and others may have undefined effects in corner cases. This article presents a testing methodology specific for CPU emulators, based on fuzzing. The emulator is “stressed” with specially crafted test cases, to verify whether the CPU is properly emulated or not. Improper behaviors of the emulator are detected by running the same test case concurrently on the emulated and on the physical CPUs and by comparing the state of the two after the execution. Differences in the final state testify defects in the code of the emulator. We implemented this methodology in a prototype (named as EmuFuzzer), analyzed five state-of-the-art IA-32 emulators (QEMU, Valgrind, Pin, BOCHS, and JPC), and found several defects in each of them, some of which can prevent proper execution of programs.
Lorenzo Martignoni, Roberto Paleari, Alessandro Reina, Giampaolo Fresi Roglia, Danilo Bruschi
ACM Trans. Softw. Eng. Methodol.5
2012 When hardware meets software: a bulletproof solution to forensic memory acquisition
abstract
The acquisition of volatile memory of running systems has become a prominent and essential procedure in digital forensic analysis and incident responses. In fact, unencrypted passwords, cryptographic material, text fragments and latest-generation malware may easily be protected as encrypted blobs on persistent storage, while living seamlessly in the volatile memory of a running system. Likewise, systems' run-time information, such as open network connections, open files and running processes, are by definition live entities that can only be observed by examining the volatile memory of a running system. In this context, tampering of volatile data while an acquisition is in progress or during transfer to an external trusted entity is an ongoing issue as it may irremediably invalidate the collected evidence.
Alessandro Reina, Aristide Fattori, Fabio Pagani, Lorenzo Cavallaro, Danilo Bruschi
ACSAC5
2010 Conqueror: Tamper-Proof Code Execution on Legacy Systems
Lorenzo Martignoni, Roberto Paleari, Danilo Bruschi
DIMVA3
2010 Testing system virtual machines
abstract
Virtual machines offer the ability to partition the resources of a physical system and to create isolated execution environments. The development of virtual machines is a very challenging task. This is particularly true for system virtual machines, since they run an operating system and must replicate in every detail the incredibly complex environment it requires. Nowadays, system virtual machines are the key component of many critical architectures. However, only little effort has been invested to test if the environment they provide is semantically equivalent to the environment found on real machines. In this paper we present a methodology specific for testing system virtual machines. This methodology is based on protocol-specific fuzzing and differential analysis, and consists in forcing a virtual machine and the corresponding physical machine to execute specially crafted snippets of user- and system-mode code and in comparing their behaviors. We have developed a prototype, codenamed KEmuFuzzer, that implements our methodology for the Intel x86 architecture and used it to test four state-of-the-art virtual machines: BOCHS, QEMU, VirtualBox and VMware. We discovered defects in all of them.
Lorenzo Martignoni, Roberto Paleari, Giampaolo Fresi Roglia, Danilo Bruschi
ISSTA4
2010 N-version disassembly: differential testing of x86 disassemblers
abstract
The output of a disassembler is used for many different purposes (e.g., debugging and reverse engineering). Therefore, disassemblers represent the first link of a long chain of stages on which any high-level analysis of machine code depends upon. In this paper we demonstrate that many disassemblers fail to decode certain instructions and thus that the first link of the chain is very weak. We present a methodology, called N-version disassembly, to verify the correctness of disassemblers, based on differential analysis. Given a set of n - 1 disassemblers, we use them to decode fragments of machine code and we compare their output against each other. To further corroborate the output of these disassemblers, we developed a special instruction decoder, the nth, that delegates the decoding to the CPU, the ideal decoder. We tested eight of the most popular disassemblers for Intel x86, and found bugs in each of them.
Roberto Paleari, Lorenzo Martignoni, Giampaolo Fresi Roglia, Danilo Bruschi
ISSTA4
2009 Surgically Returning to Randomized lib(c)
abstract
To strengthen systems against code injection attacks, the write or execute only policy (W¿X) and address space layout randomization (ASLR) are typically used in combination. The former separates data and code, while the latter randomizes the layout of a process. In this paper we present a new attack to bypass W¿X and ASLR. The state-of-the-art attack against this combination of protections is based on brute-force, while ours is based on the leakage of sensitive information about the memory layout of the process. Using our attack an attacker can exploit the majority of programs vulnerable to stack-based buffer overflows surgically, i.e., in a single attempt. We have estimated that our attack is feasible on 95.6% and 61.8% executables (of medium size) for Intel x86 and x86-64 architectures, respectively. We also analyze the effectiveness of other existing protections at preventing our attack. We conclude that position independent executables (PIE) are essential to complement ASLR and to prevent our attack. However, PIE requires recompilation, it is often not adopted even when supported, and it is not available on all ASLR-capable operating systems. To overcome these limitations, we propose a new protection that is as effective as PIE, does not require recompilation, and introduces only a minimal overhead.
Giampaolo Fresi Roglia, Lorenzo Martignoni, Roberto Paleari, Danilo Bruschi
ACSAC4
2009 Testing CPU emulators
abstract
A CPU emulator is a software that simulates a hardware CPU. Emulators are widely used by computer scientists for various kind of activities (e.g., debugging, profiling, and malware analysis). Although no theoretical limitation prevents to develop an emulator that faithfully emulates a physical CPU, writing a fully featured emulator is a very challenging and error-prone task. Modern CISC architectures have a very rich instruction set, some instructions lack proper specifications, and others may have undefined effects in corner-cases. This paper presents a testing methodology specific for CPU emulators, based on fuzzing. The emulator is "stressed" with specially crafted test-cases, to verify whether the CPU is properly emulated or not. Improper behaviours of the emulator are detected by running the same test-case concurrently on the emulated and on the physical CPUs and by comparing the state of the two after the execution. Differences in the final state testify defects in the code of the emulator. We implemented this methodology in a prototype (codenamed EmuFuzzer), analysed four state-of-the-art IA-32 emulators (QEMU, Valgrind, Pin and BOCHS), and found several defects in each of them, some of which can prevent the proper execution of programs.
Lorenzo Martignoni, Roberto Paleari, Giampaolo Fresi Roglia, Danilo Bruschi
ISSTA4
2008 On Race Vulnerabilities in Web Applications
Roberto Paleari, Davide Marrone, Danilo Bruschi, Mattia Monga
DIMVA3
2008 FluXOR: Detecting and Monitoring Fast-Flux Service Networks
Emanuele Passerini, Roberto Paleari, Lorenzo Martignoni, Danilo Bruschi
DIMVA4
2007 Static Analysis on x86 Executables for Preventing Automatic Mimicry Attacks
Danilo Bruschi, Lorenzo Cavallaro, Andrea Lanzi
DIMVA1
2007 An Efficient Technique for Preventing Mimicry and Impossible Paths Execution Attacks
abstract
In this paper we propose a new strategy for dealing with the impossible path execution (IPE) and the mimicry attack in the N-gram based HIDS model. Our strategy is based on a kernel-level module which interacts with an underlying HIDS and whose main scope is to "randomize" sequences of system calls produced by an application to make them unpredictable by any attacker. We implemented a prototype of such a module on a Linux system in order to experimentally verify the feasibility and efficacy of our idea. The results obtained are quite encouraging, furthermore it turned out that our module is quite efficient, as it affected the performance of a testbed Web server with a slowdown factor of only 5.9%.
Danilo Bruschi, Lorenzo Cavallaro, Andrea Lanzi
IPCCC1
2007 Diversified Process Replicæ for Defeating Memory Error Exploits
abstract
An interpretation of the notion of software diversity is based on the concept of diversified process replicæ. We define pr as the replica of a process p which behaves identically to p but has some "structural" diversity from it. This makes possible to detect memory corruption attacks in a deterministic way. In our solution, p and pr differ in their address space which is properly diversified, thus defeating absolute and partial overwriting memory error exploits. We also give a characterization and a preliminary solution for shared memory management, one of the biggest practical issue introduced by this approach. Speculation on how to deal with synchronous signals delivery is faced as well. A user space proof-of-concept prototype has been implemented. Experimental results show a 68.93% throughput slowdown on a worst-case, while experiencing only a 1.20% slowdown on a best-case.
Danilo Bruschi, Lorenzo Cavallaro, Andrea Lanzi
IPCCC1
2006 Detecting Self-mutating Malware Using Control-Flow Graph Matching
Danilo Bruschi, Lorenzo Martignoni, Mattia Monga
DIMVA1
2006 Software engineering for secure systems
abstract
No abstract available.
Danilo Bruschi, Bart De Win, Mattia Monga
ICSE1
2005 Replay Attack in TCG Specification and Solution
abstract
We prove the existence of a flaw which we individuated in the design of the object-independent authorization protocol (OIAP), which represents one of the building blocks of the trusted platform module (TPM), the core of the trusted computing platforms (TPs) as devised by the trusted computing group (TCG) standards. In particular, we prove, also with the support of a model checker, that the protocol is exposed to replay attacks, which could be used for compromising the correct behavior of a TP We also propose a countermeasure to undertake in order to avoid such an attack as well as any replay attacks to the aforementioned protocol
Danilo Bruschi, Lorenzo Cavallaro, Andrea Lanzi, Mattia Monga
ACSAC1
2005 Software engineering for secure systems
abstract
No abstract available
Danilo Bruschi, Bart De Win, Mattia Monga
ICSE1
2003 How to unwittingly sign non-repudiable documents with Java applications
abstract
Digital signatures allow us to produce documents whose integrity and authenticity, as we generated them, is verifiable by anybody who has access to our public key. Furthermore, we cannot repudiate those documents as something we never saw, let alone signed, since nobody else but us could access our private key. We show how the previous statement can be proved wrong when carefully crafted malicious software is installed on a machine running a Java digital signature application. By using such a software, a user may unwittingly sign another document besides the one he/she intends to digitally sign or sign a different document altogether. Our attack exploits a known vulnerability of the security architecture of the Java run-time environment that allows nonJava malicious software to replace some Java system classes with malicious ones, which then alter the victim application behavior.
Danilo Bruschi, D. Fabris, V. Glave, Emilia Rosti
ACSAC1
2003 S-ARP: a Secure Address Resolution Protocol
abstract
Tapping into the communication between two hosts on a LAN has become quite simple thanks to tools that can be downloaded from the Internet. Such tools use the address resolution protocol (ARP) poisoning technique, which relies on hosts caching reply messages even though the corresponding requests were never sent. Since no message authentication is provided, any host of the LAN can forge a message containing malicious information. We present a secure version of ARP that provides protection against ARP poisoning. Each host has a public/private key pair certified by a local trusted party on the LAN, which acts as a certification authority. Messages are digitally signed by the sender, thus preventing the injection of spurious and/or spoofed information. As a proof of concept, the proposed solution was implemented on a Linux box. Performance measurements show that PKI based strong authentication is feasible to secure even low level protocols, as long as the overhead for key validity verification is kept small.
Danilo Bruschi, A. Ornaghi, Emilia Rosti
ACSAC1
2003 A quantitative study of Public Key Infrastructures
Danilo Bruschi, A. Curti, Emilia Rosti
Comput. Secur.1
2002 Voice over IPsec: Analysis and Solutions
abstract
In this paper we present the results of the experimental analysis of the transmission of voice over secure communication links implementing IPsec. Critical parameters characterizing the real-time transmission of voice over an IPsec-ured Internet connection, as well as techniques that could be adopted to overcome some of the limitations of VoIPsec (Voice over IPsec), are presented Our results show that the effective bandwidth can be reduced up to 50% with respect to VoIP in case of VoIPsec. Furthermore, we show that the cryptographic engine may hurt the performance of voice traffic because of the impossibility to schedule the access to it in order to prioritize traffic. We present an efficient solution for packet header compression, which we call cIPsec, for VoIPsec traffic. Simulation results show that the proposed compression scheme significantly reduces the overhead of packet headers, thus increasing the effective bandwidth used by the transmission. In particular, when cIPsec is adopted, the average packet size is only 2% bigger than in the plain case (VoIP), which makes VoIPsec and VoIP equivalent from the bandwidth usage point of view.
Roberto Barbieri, Danilo Bruschi, Emilia Rosti
ACSAC2
2002 Secure Multicast in Wireless Networks of Mobile Hosts: Protocols and Issues
Danilo Bruschi, Emilia Rosti
Mob. Networks Appl.1
2001 Secure pebblenets
abstract
We consider the problem of securing communication in large ad hoc networks, i.e., wireless networks with no fixed, wired infrastructure and with multi-hop routes. Such networks, e.g., networks of sensors, are deployed for applications such as microsensing, monitoring and control, and for extending the peer-to-peer communication capability of smaller group of network users. Because the nodes of these networks, which we term pebbles for their very limited size and large number, are resource constrained, only symmetric key cryptography is feasible. We propose a key management scheme to periodically update the symmetric keys used by all pebbles. By combining mobility-adaptive clustering and an effective probabilistic selection of the key-generating node, the proposed scheme meets the requirements of efficiency, scalability and security needed for the survivability of networks of pebbles (pebblenets)
Stefano Basagni, Kris Herrin, Danilo Bruschi, Emilia Rosti
MobiHoc3
2001 AngeL: a tool to disarm computer systems
abstract
In this paper we present a tool designed to intercept attacks at the host where they are launched so as to block them before they reach their targets. The tool works both for attacks targeted on the local host and on hosts connected to the network. In the current implementation it can detect and block more than 70 attacks as reported in the literature.The tool is based on the idea of improving the overall security of the Internet by connecting disarmed systems, i.e., hosts that cannot launch attacks against other hosts. Such a strategy was presented in [4]. Here we present an extended version of the tool that has been engineered to consider a wide variety of attacks and to run on various releases of the Linux kernel and the experience learned in building such a tool. A protection mechanism of the tool itself that prevents its removal is also implemented. Experimental results of the impact of the tool on system performance show that the overhead introduced by the tool is negligible from the user's perspective, thus it is not expected to be a hindrance to the successful deployment of the tool.
Danilo Bruschi, Emilia Rosti
NSPW1
2000 Less Harm, Less Worry or How to Improve Network Security by Bounding System Offensiveness
abstract
We describe a new class of tools for protecting computer systems from security attacks. Their distinguished feature is the principle they are based on. Host or network protection is not achieved by strengthening their defenses but by weakening the enemy's offensive capabilities. A prototype tool has been implemented that demonstrates that such an approach is feasible and effective. We show that some of the most popular DoS attacks are effectively blocked with limited impact on the sender's performance. Measurements of the implemented prototype show that controlling the outgoing traffic does not affect performance at the sender machine, when traffic is not hostile. If traffic is hostile, the limited slow down experienced at the source is the price to pay to make the Internet a safer place for all its users. The limited performance impact and the efficacy in attack prevention make tools like the one presented a new component of security architectures. Furthermore, such a type of tools represents an effective way to address security problems that are still unsolved or for which only partial solutions are available, such as the liability problem, intranet security, security tools performance and the use of distributed tools for intrusion.
Danilo Bruschi, Lorenzo Cavallaro, Emilia Rosti
ACSAC1
2000 Disarming offense to facilitate defense
abstract
Computer security has traditionally focused on system defense, concentrating on victim machines protection and recovery. Moving from the opposite perspective, we propose a matching approach that focuses on limiting the attacking capabilities of the hosts. Software design and implementation weaknesses usually are at the basis of computer offensive capacities. Since software redesign or patching on an extensive basis is not possible, we propose the introduction of a filtering strategy to block abuse attempts at the originating machines. As an example, applications of such an approach are presented at network level, in order to prevent popular DoS attacks, among others. The proposed
Danilo Bruschi, Emilia Rosti
NSPW1
2000 A logarithmic lower bound for time-spread multiple-access (TSMA) protocols
Stefano Basagni, Danilo Bruschi
Wirel. Networks2
1999 Adding Availability to Log Services of Untrusted Machines
abstract
Uncorrupted log files are the critical system component for computer forensics in case of intrusion and for real time system monitoring and auditing. Protection from tampering with information can be achieved using cryptographic functions that provide authenticity, integrity, and confidentiality. However, they cannot provide the prerequisite for any further information processing, i.e., information availability. In this case, fault tolerant strategies can be of great help improving information availability in case of accidental or deliberate deletion. In this paper we propose a system that increases log file availability in case of software deletion by reliably and efficiently distributing the logs on multiple independent machines. The proposed scheme is more efficient than simple replication, both from the storage space and the network bandwidth points of view. The proposed system has been implemented and its impact on performance has been measured. Since it operates as a postprocessor after log generation, the proposed system can be easily integrated with logging systems that provide various cryptographic functions for forensic purposes.
Arianna Arona, Danilo Bruschi, Emilia Rosti
ACSAC2
1999 A mobility-transparent deterministic broadcast mechanism for ad hoc networks
abstract
Broadcast (distributing a message from a source node to all other nodes) is a fundamental problem in distributed computing. Several solutions for solving this problem in mobile wireless networks are available, in which mobility is dealt with either by the use of randomized retransmissions or, in the case of deterministic delivery protocols, by using conflict-free transmission schedules. Randomized solutions can be used only when unbounded delays can be tolerated. Deterministic conflict-free solutions require schedule recomputation when topology changes, thus becoming unstable when the topology rate of change exceeds the schedule recomputation rate. The deterministic broadcast protocols we introduce in this paper overcome the above limitations by using a novel mobility-transparent schedule, thus providing a delivery (time) guarantee without the need to recompute the schedules when topology changes. We show that the proposed protocol is simple and easy to implement, and that it is optimal in networks in which assumptions on the maximum number of the neighbors of a node can be made.
Stefano Basagni, Imrich Chlamtac, Danilo Bruschi
IEEE/ACM Trans. Netw.3
1998 A Tool for Pro-active Defense Against the Buffer Overrun Attack
Danilo Bruschi, Emilia Rosti, R. Banfi
ESORICS1
1997 Lower Bounds for the Broadcast Problem in Mobile Radio Networks
Danilo Bruschi, Massimiliano Del Pinto
Distributed Comput.1
1995 Random Parallel Algorithms for Finding Exact Branchings, Perfect Matchings, and Cycles
Danilo Bruschi, F. Ravasio
Algorithmica1
1994 On the Existence of Minimum Asynchronous Automata and on the Equivalence Problem for Unambiguous Regular Trace Languages
Danilo Bruschi, Giovanni Pighizzini, Nicoletta Sabadini
Inf. Comput.1
1993 The Complexity of Computing Maximal Word Functions
Eric Allender, Danilo Bruschi, Giovanni Pighizzini
Comput. Complex.2
1992 Strong Separations of the Polynomial Hierarchy with Oracles: Constructive Separations by Immune and Simple Sets
Danilo Bruschi
Theor. Comput. Sci.1
1991 The Complexity of Computing Maximal Word Functions
Danilo Bruschi, Giovanni Pighizzini
FCT1
1991 Ranking and Formal Power Series
Alberto Bertoni, Danilo Bruschi, Massimiliano Goldwurm
Theor. Comput. Sci.2
1989 Generalized Boolean Hierarchies and Boolean Hierarchies Over RP (Conference Abstract)
Alberto Bertoni, Danilo Bruschi, Deborah Joseph, Meera Sitharam, Paul Young
FCT2
1988 On the Existence of the Minimum Asynchronous Automaton and on Decision Problems for Unambiguous Regular Trace Languages
Danilo Bruschi, Giovanni Pighizzini, Nicoletta Sabadini
STACS1