Saverio Giallorenzo

dblp:146/2078 · DBLP profile ↗
← Back
41ranked-venue papers
13as first author
32since 2021 · last 2026
0000-0002-3658-6395ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 23 · 8 first-author · 18 since 2021Security and privacy · 6 · 1 first-author · 5 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Theory of computation · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 WIP: Ad-Hoc Network Serverless Scheduling in an Industrial Case Study: Drone Swarms in Disaster-Struck Urban Environments
Saverio Giallorenzo, Angelo Trotta, F. Bernardi, R. Morelli, A. Remus, A. Santopaolo, F. Schiano, Gianluigi Zavattaro
WoWMoM1
2026 SAFARI: A Scalable Air-gapped Framework for Automated Ransomware Investigation
Tommaso Compagnucci, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini
Comput. Secur.2
2026 Function-specific scheduling policies in cloud-edge serverless systems
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
Future Gener. Comput. Syst.2
2026 Choreography-defined networks: Concepts and a case study on AI-based attack detection
abstract
Modern network infrastructures increasingly rely on Software-Defined Networking (SDN) and Network Function Virtualisation (NFV) to achieve flexibility, scalability, and efficiency. While these paradigms facilitate the deployment of Cloud-native Network Functions (CNF), they lack tools for high-level programming and guarantees on correct multi-component compositions. We introduce Choreography-Defined Networking (CDN), a methodology that applies choreographic programming to the specification and implementation of SDN compositions. In CDN, developers write a single global choreography that describes interactions among CNFs and a compiler generates endpoint code that coordinate them as specified in the choreography. CDN delivers correctness-by-construction guarantees – including deadlock freedom and communication-type safety – while eliminating the need for a centralised orchestrator, replaced by direct, parallel communication among CNFs. To evaluate our methodology, we use CDN to design and implement a case study on a distributed, AI-enhanced SDN composition for volumetric attack detection and mitigation, in which four CNFs collaboratively analyse traffic using volumetric anomaly inspection, machine-learning classification, and signature matching. We compare this CDN implementation against two SDN baselines: a classical controller-driven chain and a hybrid solution that repurposes network traffic as a management channel. Experiments across four representative attack scenarios show that the CDN approach reduces mean decision latency by approximately 15% over both baselines, while generating up to 80% less management traffic. These results confirm that CDN allows to raise the abstraction level at which one writes distributed SDN compositions without compromising – actually improving – runtime performance in real-world network deployments.
Saverio Giallorenzo, Jacopo Mauro, Andrea Melis 0001, Fabrizio Montesi, Marco Peressotti, Marco Prandini
Inf. Softw. Technol.1
2026 tAPP OpenWhisk: A serverless platform for topology-aware allocation priority policies
abstract
The Function-as-a-Service (FaaS) paradigm offers a serverless approach that abstracts the management of underlying infrastructure, enabling developers to focus on application logic. However, leveraging infrastructure-aware features can further optimize serverless performance. We present a software prototype that enhances Apache OpenWhisk serverless platform with a novel architecture incorporating tAPP (topology-aware Allocation Priority Policies), a declarative language designed for specifying topology-aware scheduling policies. Through a case study involving distributed data access across multiple cloud regions, we show that tAPP can significantly reduce latency and minimizes performance variability compared to the standard OpenWhisk implementation.
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
Sci. Comput. Program.2
2026 A Constraint-Based Approach to Optimise QoS- and Energy-Aware Cloud-Edge Application Deployments
abstract
Cloud-Edge application deployment involves placing multiple software components on infrastructural topologies of heterogeneous nodes, ranging from Cloud servers to Internet-of-Things (IoT) edge devices. When multiple versions (or “ flavours ”) of a component are available, application managers must select a flavour for each deployed component, and assign these components to specific nodes, all while considering constraints such as dependencies, quality of service (QoS), budget, operational costs, and carbon emissions. In complex scenarios, finding the optimal deployment is often infeasible for human operators without automated tools to systematically explore the solution space. To address this challenge, we introduce FREEDA, a first constraint optimisation approach for deploying constrained and multi-flavoured applications on Cloud-Edge infrastructure topologies. We demonstrate the practical feasibility of FREEDA through experiments on a variety of realistic Cloud-Edge infrastructural topologies and component architectures. Furthermore, we benchmark FREEDA against Zephyrus, a comparable tool employing the same underlying solving technology. Empirical results show that FREEDA achieves strong scalability across a broad spectrum of realistic configurations and consistently outperforms Zephyrus.
Simone Gazza, Roberto Amadini, Antonio Brogi, Andrea D'Iapico, Stefano Forti 0002, Saverio Giallorenzo, Pierluigi Plebani, Francisco Ponce 0001, Jacopo Soldani, Monica Vitali, Gianluigi Zavattaro
ACM Trans. Internet Techn.6
2025 Affinity-aware Serverless Function Scheduling
abstract
Functions-as-a-Service (FaaS) is a Serverless Cloud paradigm where a platform manages the scheduling (e.g., resource allocation, runtime environments) of stateless functions. Recent work proposed using domain-specific languages to express per-function policies, e.g., policies that enforce the allocation on nodes that enjoy lower latencies to databases and services used by the function. Here, we focus on affinity-aware scenarios, i.e., where, for performance and functional requirements, the allocation of a function depends on the presence/absence of other functions on nodes. We present aAPP, an extension of a declarative, platform-agnostic language that captures affinity-aware scheduling at the FaaS level. We implement an aAPP-based prototype on Apache OpenWhisk. Besides proving that a FaaS platform can capture affinity awareness using aAPP and improve performance in affinity-aware scenarios, we use our prototype to show that aAPP imposes no noticeable overhead in scenarios without affinity constraints.
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
ICSA2
2025 Reachability Analysis of Function-as-a-Service Scheduling Policies
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
iFM2
2025 SAFARI: A Scalable Air-Gapped Framework for Automated Ransomware Investigation
abstract
Ransomware poses a significant threat to individuals and organisations, creating a need for tools to investigate its behaviour and the effectiveness of mitigations. To address this need, we present SAFARI, an open-source framework designed for safe and efficient ransomware analysis. SAFARI’s design emphasises scalability, air-gapped security, and automation, democratising access to safe ransomware investigation tools and fostering collaborative efforts. SAFARI leverages virtualisation, Infrastructure-as-Code, and OS-agnostic task automation to create isolated environments for controlled ransomware execution and analysis. The framework enables researchers to profile ransomware behaviour and evaluate mitigation strategies through automated, reproducible experiments. We demonstrate SAFARI’s capabilities by building a proof-of-concept implementation and using it to conduct two case studies: the first analyses seven ransomware strains – including WannaCry and LockBit – to identify their encryption patterns and file-targeting strategies; the second evaluates Ranflood, a countermeasure tool, against five dangerous strains. Our results provide insights into ransomware behaviour and the effectiveness of countermeasures, showcasing SAFARI’s potential to advance ransomware research and defence development.
Tommaso Compagnucci, Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Alessandro Vannini
SEC (1)3
2025 Contrasting Crypto and Exfiltration Ransomware with Shamir's Secret Sharing Data Flooding
abstract
Ransomware poses a significant threat to both Individuals and organizations, with crypto-ransomware and exfiltration attacks causing widespread damage, financial loss, and operational disruption. Ranflood is a ransomware attack mitigation tool that confuses and overwhelms attackers by flooding the system with decoy files, thereby slowing down the attack and providing a critical window for intervention. In this paper, we extend the coverage provided by Ranflood with a new, advanced flooding strategy based on Shamir’s Secret Sharing (SSS) to counteract both crypto-and exfiltration ransomware. Our SSS-based strategy confounds ransomware by generating many shards from each user’s file, which we tune for high resilience when contrasting crypto-ransomware (so that the user can regain access to lost data from a few shards) and secrecy against exfiltration (so that the attacker needs many shards to recover the victim’s data). We explore the theoretical and practical challenges of applying SSS in this context, present the design and implementation details of our flooder, and empirically evaluate and profile its performance.
Daniele D'Ugo, Saverio Giallorenzo, Simone Melloni
TrustCom2
2025 Reliable and Robust Watermarking for Data Flooding against Ransomware Random Techniques
abstract
Data Flooding Against Ransomware (DFaR) techniques combat ransomware through decoy files that can reveal a ransomware’s activity and reduce the effectiveness and efficiency of attacks by confounding legitimate user files and competing for IO resource access of the attacked host. While effective, existing DFaR random strategies (which flood a user system with realistic yet random-content decoy files) face challenges during restoration, due to the necessity of pre-attack file lists to discriminate between proper and decoy files (the latter should be removed to restore the system to its pre-attack state). To tackle this issue, we present a watermarking-based approach that embeds imperceptible watermarks in random-content decoy files. Our technique preserves the indistinguishability of decoys from user files to attackers, while providing users with a reliable mechanism to differentiate between authentic and decoy content, obviating the need for pre-attack file lists. We present experimental evaluations that demonstrate that our watermarking technique a) imposes minimal-to-medium computational overhead (depending on user-configurable parameters) compared to existing random-content flooding methods (i.e., it is efficient when contrasting ransomware and restoring a user’s system) and b) it provides strong resistance against adversarial inference attacks.
Saverio Giallorenzo, Simone Melloni, Pietro Sami
TrustCom1
2025 Distributed serverless function scheduling in ad-hoc drone networks
Giuseppe De Palma, Saverio Giallorenzo, Alexandre Heideker, Matteo Trentin, Angelo Trotta, Gianluigi Zavattaro
Ad Hoc Networks2
2025 Investigating operational technology attacks as code
abstract
Abstract Industrial Operational Technology (OT) environments face escalating cybersecurity challenges due to increasing interconnectedness, device heterogeneity, and the integration of legacy systems not designed with modern security requirements. Operators struggle with security validation in OT settings due to the complexity of static reasoning across multilayered architectures and the impracticality of in-production testing, which risks operational disruptions and safety hazards. To address these limitations, we propose SAFARI, a framework that leverages the concepts of digital twin and cyber range to enable Security-Investigation-as-Code for OT environments, automating the creation, deployment, and security testing of faithful OT architecture replicas. SAFARI uses technologies such as Terraform, Proxmox SDN, and MITRE Caldera to provide scalable, reproducible security assessment capabilities while maintaining complete air-gapping for safe malware testing. We demonstrate SAFARI’s effectiveness through a comprehensive case study examining three industrial network architectures exhibiting increasing segmentation. Our results show that SAFARI successfully automates complex security scenarios, enables regression testing of architectural refinements, and provides quantifiable insights into attack resistance improvements. The framework represents a significant advancement in OT security testing methodology, offering security operators a practical tool for systematic vulnerability assessment and architectural validation without compromising operational continuity.
Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini
Empir. Softw. Eng.2
2025 Proactive-reactive microservice architecture global scaling
Lorenzo Bacchiani, Mario Bravetti, Saverio Giallorenzo, Maurizio Gabbrielli, Gianluigi Zavattaro, Stefano Pio Zingaro
J. Syst. Softw.3
2025 JoT: A Jolie framework for testing microservices
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, Florian Rademacher, Narongrit Unwerawattana
Sci. Comput. Program.1
2024 An OpenWhisk Extension for Topology-Aware Allocation Priority Policies
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
COORDINATION2
2024 Choreography-Defined Networks: A Case Study on DoS Mitigation
Saverio Giallorenzo, Jacopo Mauro, Andrea Melis 0001, Fabrizio Montesi, Marco Peressotti, Marco Prandini
ICSOC (2)1
2024 A Toolchain for Checking Domain- and Model-Driven Properties of Jolie Microservices
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, Florian Rademacher, Sabine Sachweh, Philip Wizenty
ICSOC (2)1
2024 FunLess: Functions-as-a-Service for Private Edge Cloud Systems
abstract
Serverless computing has extended its reach to encompass private edge cloud systems, aiming to enhance latency, security, and privacy while optimising resource usage. However, this extension comes with challenges such as running platforms and functions on disparate and resource-constrained devices. To respond to the challenges, we present FunLess, a Function-as-a-Service (FaaS) platform tailored for private edge cloud systems. Unlike conventional solutions relying on container technologies for function invocation, FunLess leverages WebAssembly (Wasm) as its runtime environment. This choice offers several advantages, including inherent security and isolation mechanisms crucial for data integrity and confidentiality, portability and consistent development and deployment, and a reduced memory footprint that allows functions to run on constrained edge devices.
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
ICWS2
2024 Function-as-a-Service Allocation Policies Made Formal
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
ISoLA (1)2
2024 Pick a Flavour: Towards Sustainable Deployment of Cloud-Edge Applications
Roberto Amadini, Simone Gazza, Jacopo Soldani, Monica Vitali, Antonio Brogi, Stefano Forti 0002, Saverio Giallorenzo, Pierluigi Plebani, Francisco Ponce 0001, Gianluigi Zavattaro
LOPSTR7
2024 Leveraging static analysis for cost-aware serverless scheduling policies
Giuseppe De Palma, Saverio Giallorenzo, Cosimo Laneve, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
Int. J. Softw. Tools Technol. Transf.2
2024 Choral: Object-oriented Choreographic Programming
abstract
Choreographies are coordination plans for concurrent and distributed systems, which define the roles of the involved participants and how they are supposed to work together. In the paradigm of choreographic programming, choreographies are programs that can be compiled into executable implementations. In this article, we present Choral, the first choreographic programming language based on mainstream abstractions. The key idea in Choral is a new notion of data type, which allows for expressing that data is distributed over different roles. We use this idea to reconstruct the paradigm of choreographic programming through object-oriented abstractions. Choreographies are classes, and instances of choreographies are objects with states and behaviours implemented collaboratively by roles. Choral comes with a compiler that, given a choreography, generates an implementation for each of its roles. These implementations are libraries in pure Java, whose types are under the control of the Choral programmer. Developers can then modularly compose these libraries in their programs, to participate correctly in choreographies. Choral is the first incarnation of choreographic programming offering such modularity, which finally connects more than a decade of research on the paradigm to practical software development. The integration of choreographic and object-oriented programming yields other powerful advantages, where the features of one paradigm benefit the other in ways that go beyond the sum of the parts. On the one hand, the high-level abstractions and static checks from the world of choreographies can be used to write concurrent and distributed object-oriented software more concisely and correctly. On the other hand, we obtain a much more expressive choreographic language from object-oriented abstractions than in previous work. This expressivity allows for writing more reusable and flexible choreographies. For example, object passing makes Choral the first higher-order choreographic programming language, whereby choreographies can be parameterised over other choreographies without any need for central coordination. We also extend method overloading to a new dimension: specialisation based on data location. Together with subtyping and generics, this allows Choral to elegantly support user-defined communication mechanisms and middleware.
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti
ACM Trans. Program. Lang. Syst.1
2023 JoT: A Jolie Framework for Testing Microservices
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, Florian Rademacher, Narongrit Unwerawattana
COORDINATION1
2023 Data Flooding against Ransomware: Concepts and Implementations
abstract
Ransomware is one of the most infamous kinds of malware, particularly the “crypto” subclass, which encrypts users’ files, asking for some monetary ransom in exchange for the decryption key. Recently, crypto-ransomware grew into a scourge for enterprises and governmental institutions. The most recent and impactful cases include an oil company in the US, an international Danish shipping company, and many hospitals and health departments in Europe. Attacks result in production lockdowns, shipping delays, and even risks to human lives. To contrast ransomware attacks (crypto, in particular), we propose a family of solutions, called Data Flooding against Ransomware, tackling the main phases of detection, mitigation, and restoration, based on a mix of honeypots, resource contention, and moving target defence. These solutions hinge on detecting and contrasting the action of ransomware by flooding specific locations (e.g., the attack location, sensible folders, etc.) of the victim’s disk with files. Besides the abstract definition of this family of solutions, we present an open-source tool that implements the mitigation and restoration phases, called Ranflood. In particular, Ranflood supports three flooding strategies, apt for different attack scenarios. At its core, Ranflood buys time for the user to counteract the attack, e.g., to access an unresponsive, attacked server and shut it down manually. We benchmark the efficacy of Ranflood by performing a thorough evaluation over 6 crypto-ransomware (e.g., WannaCry, LockBit) for a total of 78 different attack scenarios, showing that Ranflood consistently lowers the amount of files lost to encryption.
Davide Berardi, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Loris Onori, Marco Prandini
Comput. Secur.2
2023 LEMMA2Jolie: A tool to generate microservice APIs from domain models
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, Florian Rademacher
Sci. Comput. Program.1
2022 Model-Driven Generation of Microservice Interfaces: From LEMMA Domain Models to Jolie APIs
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, Florian Rademacher
COORDINATION1
2022 Proactive-Reactive Global Scaling, with Analytics
Lorenzo Bacchiani, Mario Bravetti, Maurizio Gabbrielli, Saverio Giallorenzo, Gianluigi Zavattaro, Stefano Pio Zingaro
ICSOC4
2022 A Declarative Approach to Topology-Aware Serverless Function-Execution Scheduling
abstract
State-of-the-art serverless platforms use hard-coded scheduling policies that are unaware of the possible topological constraints of functions. Considering these constraints when scheduling functions leads to sensible performance improvements, e.g., minimising loading times or data-access latencies. This issue becomes more pressing when considered in the emerging multi-cloud and edge-cloud-continuum systems, where only specific nodes can access specialised, local resources. To address this problem, we present a declarative language for defining serverless scheduling policies to express constraints on topologies of schedulers and execution nodes. We implement our approach as an extension of the OpenWhisk platform.
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Matteo Trentin, Gianluigi Zavattaro
ICWS2
2021 Microservice Dynamic Architecture-Level Deployment Orchestration
Lorenzo Bacchiani, Mario Bravetti, Saverio Giallorenzo, Jacopo Mauro, Iacopo Talevi, Gianluigi Zavattaro
COORDINATION3
2021 Jolie and LEMMA: Model-Driven Engineering and Programming Languages Meet on Microservices
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, Florian Rademacher, Sabine Sachweh
COORDINATION1
2021 Multiparty Languages: The Choreographic and Multitier Cases (Pearl)
abstract
Choreographic languages aim to express multiparty communication protocols, by providing primitives that make interaction manifest. Multitier languages enable programming computation that spans across several tiers of a distributed system, by supporting primitives that allow computation to change the location of execution. Rooted into different theoretical underpinnings - respectively process calculi and lambda calculus - the two paradigms have been investigated independently by different research communities with little or no contact. As a result, the link between the two paradigms has remained hidden for long. In this paper, we show that choreographic languages and multitier languages are surprisingly similar. We substantiate our claim by isolating the core abstractions that differentiate the two approaches and by providing algorithms that translate one into the other in a straightforward way. We believe that this work paves the way for joint research and cross-fertilisation among the two communities.
Saverio Giallorenzo, Fabrizio Montesi, Marco Peressotti, David Richter 0001, Guido Salvaneschi, Pascal Weisenburger
ECOOP1
2020 Allocation Priority Policies for Serverless Function-Execution Scheduling Optimisation
Giuseppe De Palma, Saverio Giallorenzo, Jacopo Mauro, Gianluigi Zavattaro
ICSOC2
2019 No More, No Less - A Formal Model for Serverless Computing
Maurizio Gabbrielli, Saverio Giallorenzo, Ivan Lanese, Fabrizio Montesi, Marco Peressotti, Stefano Pio Zingaro
COORDINATION2
2019 Optimal and Automated Deployment for Microservices
abstract
Microservices are highly modular and scalable Service Oriented Architectures. They underpin automated deployment practices like Continuous Deployment and Autoscaling. In this paper we formalize these practices and show that automated deployment — proven undecidable in the general case — is algorithmically treatable for microservices. Our key assumption is that the configuration life-cycle of a microservice is split into two phases: (i) creation, which entails establishing initial connections with already available microservices, and (ii) subsequent binding/unbinding with other microservices. To illustrate the applicability of our approach, we implement an automatic optimal deployment tool and compute deployment plans for a realistic microservice architecture, modeled in the Abstract Behavioral Specification (ABS) language.
Mario Bravetti, Saverio Giallorenzo, Jacopo Mauro, Iacopo Talevi, Gianluigi Zavattaro
FASE2
2018 Applied Choreographies
Saverio Giallorenzo, Fabrizio Montesi, Maurizio Gabbrielli
FORTE1
2018 Cloud-of-Things meets Mobility-as-a-Service: An insider threat perspective
Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Marco Prandini
Comput. Secur.2
2015 Dynamic Choreographies - Safe Runtime Updates of Distributed Applications
Mila Dalla Preda, Maurizio Gabbrielli, Saverio Giallorenzo, Ivan Lanese, Jacopo Mauro
COORDINATION3
2015 Developing correct, distributed, adaptive software
Mila Dalla Preda, Maurizio Gabbrielli, Saverio Giallorenzo, Ivan Lanese, Jacopo Mauro
Sci. Comput. Program.3
2014 Towards a Composition-based APIaaS Layer
abstract
Application Programming Interfaces (APIs) are a standard feature of any application that exposes its functionalities to external invokers. APIs can be composed thus obtaining new programs with new functionalities. However API composition can easily become a frustrating task which often prevents developers from using this possibility when implementing and publishing new applications. This fact is due to several specific features of API composition performed using current technology, such as the need of extensive documentation, the need of protocol integration, security issues and others. In this paper we introduce a view of the API as a Service (APIaaS) layer as a tool which ease the development and deployment of applications based on API compositions, by abstracting communication protocols and message formats. We elicit the desirable features of such a layer and provide a proof-of-concept prototype implemented using a Service Oriented language.
Claudio Guidi, Saverio Giallorenzo, Maurizio Gabbrielli
CLOSER2
2014 AIOCJ: A Choreographic Framework for Safe Adaptive Distributed Applications
Mila Dalla Preda, Saverio Giallorenzo, Ivan Lanese, Jacopo Mauro, Maurizio Gabbrielli
SLE2