EDBT 2026 Demo / reviewers in the wild / expert
Leonardo Regano
dblp:185/7991
· DBLP profile ↗
14ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-9259-5157ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 6 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automatic selection of protections to mitigate risks against software applicationsabstractThis paper introduces a novel approach for the automated selection of software protections to mitigate Machine-At-The-End risks against critical assets within software applications. We formalize the key elements involved in protection decision-making — including code artifacts, assets, security requirements, attacks, and software protections — and frame the protection process through a model inspired by game theory. In this model, a defender strategically applies protections to various code artifacts of a target application, anticipating repeated attack attempts by adversaries against the confidentiality and integrity of the application’s assets. The selection of the optimal defense maximizes resistance to attacks while ensuring the application remains usable by constraining the overhead introduced by protections. The game is solved through a heuristic based on a mini-max depth-first exploration strategy, augmented with dynamic programming optimizations for improved efficiency. Central to our formulation is the introduction of the Software Protection Index, an original contribution that extends existing notions of potency and resilience by evaluating protection effectiveness against attack paths using software metrics and expert assessments. We validate our approach through a proof-of-concept implementation and expert evaluations, demonstrating that automated software protection is a practical and effective solution for risk mitigation in software. Daniele Canavese, Leonardo Regano, Cataldo Basile, Bjorn De Sutter |
Comput. Secur. | 2 |
| 2026 | Race against time: investigating the factors that influence web race condition exploitsabstractRace conditions (RC) pose a critical security threat to web applications by exploiting the non-deterministic behavior of multithreaded request handling. This can lead to unpredictable outcomes such as data corruption, Time of Check to Time of Use (TOCTOU) vulnerabilities, and deadlocks. While previous research has identified poor design practices that contribute to RC vulnerabilities, no existing studies have explored the factors that influence the severity or impact of race conditions. This paper introduces a comprehensive methodology for testing and quantifying how different variables affect the exploitability of race conditions in vulnerable web servers, providing a framework for future research to investigate this issue more thoroughly. In addition, we present an experimental evaluation of our methodology under various conditions. Specifically, we examine six RC exploitation tools using four different attack techniques across both HTTP/1.1 and HTTP/2 protocols. To provide a complete overview of race conditions across all HTTP versions, we also introduce the first race condition attack tool for HTTP/3, named QUICker. Furthermore, we assess how the choice of database management systems and programming languages used in web application deployment can affect susceptibility to race condition attacks. This study offers key insights into how these factors influence the exploitability of RC vulnerabilities. Federico Loi, Lorenzo Pisu, Leonardo Regano, Davide Maiorca, Giorgio Giacinto |
Comput. Secur. | 3 |
| 2026 | Empirical assessment of the code comprehension effort needed to attack programs protected with obfuscationabstractEvaluating the effectiveness of software protection is crucial for selecting the most effective methods to safeguard assets within software applications. Obfuscation involves techniques that deliberately modify software to make it more challenging to understand and reverse-engineer, while maintaining its original functionality. Although obfuscation is widely adopted, its effectiveness remains largely unexplored and not rigorously evaluated. This paper presents a controlled experiment involving Master’s students performing code comprehension tasks on applications hardened with obfuscation. The experiment’s goals are to assess the effectiveness of obfuscation in delaying code comprehension by attackers and to determine whether complexity metrics can accurately predict the impact of these protections on success rates and durations of code comprehension tasks. The study is the first to evaluate the effect of layering multiple obfuscation techniques on a single piece of protected code. It also provides experimental evidence of the correlation between objective metrics of the attacked code and the likelihood of a successful attack, bridging the gap between objective and subjective approaches to estimating potency. Finally, the paper highlights significant aspects that warrant additional analysis and opens new avenues for further experiments. Leonardo Regano, Daniele Canavese, Cataldo Basile, Marco Torchiano |
Comput. Secur. | 1 |
| 2026 | Statistical effort modelling of game resource localisation attacksabstractEvidence on the effectiveness of ManMachine-At-The-End (MATE) software protections, such as code obfuscation, has mainly come from limited empirical research. Recently, however, a meta-model and an automatable method waswere proposed to obtain statistical models of the required effort to attack (protected) software. The proposed method was sketched for a number of attack strategies but not instantiated, evaluated, or validated for those that require human interaction with the attacked software. In this paper, we present an fullend-to-end instantiation, formalisation, implementation, and validation of thethat existing meta-model and method to obtain statistical effort models for game resource localisation attacks, which represent a major step towards creating game cheats, a prime example of MATE attacks. We discuss in detail all relevant aspects of our instantiation and the results obtained for two game use cases. Our results confirm the feasibility of the proposedexisting meta-model and method, and itstheir utility for decision support for users of software protection tools. These results open up a new avenue for obtaining models of the impact of software protections on reverse engineering attacks, which will scale much better than empirical research involving human participants. Alessandro Sanna, Waldo Verstraete, Leonardo Regano, Davide Maiorca, Bjorn De Sutter |
Comput. Secur. | 3 |
| 2025 | Evaluation of Resource-Aware HTTP/3 Proxies for Smuggling Resilience in IoT EnvironmentsabstractThe growing integration of IoT devices into Edge and Fog infrastructures, alongside the increasing adoption of low-latency QUIC-based protocols like HTTP/3, has intensified the need for lightweight, resource-efficient security mechanisms to counter emerging threats such as request smuggling. Within this context, proxy-based architectures offer an optimal trade-off to strengthen network security while accommodating the limited computational capacity of IoT devices. In this direction, this paper presents a comprehensive experimental evaluation of the impact of different proxies for HTTP/3 services on resource usage when deployed on platforms such as the Raspberry Pi (RPi), considering diverse traffic patterns, operational conditions, and device configurations. The results highlight that proxies can achieve a promising balance between security and resource overhead, confirming their viability for integration into distributed IoT-based Edge and Fog networks. Lorenzo Pisu, Giovanni Pettorru, Leonardo Regano, Davide Maiorca, Giorgio Giacinto, Marco Martalò |
GLOBECOM | 3 |
| 2025 | Analysis and Detection of Android Stegomalware: the Impact of the Loading StageabstractDue to the increasing use of advanced offensive techniques, the mitigation of Android malware is an urgent need.An emerging attack trend exploits steganography to conceal malicious payloads within applications to make attacks stealthier.Even if works on "stegomalware" are starting to emerge, they primarily focus on the multimedia part of the attack chain, i.e., on how to detect hidden data in images or videos.Therefore, this work aims at understanding whether the loading stage required for the extraction of cloaked information can generate detection signatures.To this aim, we develop a proofof-concept implementation, which has been repacked within a real Android application and tested against several malware detection engines provided by VirusTotal.To anticipate possible offensive campaigns, we also performed tests by considering threat actors able to obfuscate the bytecode of the loader or the entire APK.Results indicate that standard tools are not ready to face stegomalware targeting Android applications.Therefore, we provide indications on how to improve forensics and attribution phases for Android malware endowed with information hiding capabilities. Diego Soi, Silvia Lucia Sanna, Giacomo Benedetti, Angelica Liguori, Leonardo Regano, Luca Caviglione, Giorgio Giacinto |
IH&MMSec | 5 |
| 2023 | A Model for Automated Cybersecurity Threat Remediation and SharingabstractThis paper presents an approach to the automatic remediation of threats reported by Cyber Threat Intelligence. Remediation strategies, named Recipes, are expressed in a close-to-natural language for easy validation. Thanks to the developed models, they are interpreted, contextualized, and then translated into CACAO Security playbooks, a standard format ready for automatic enforcement, without human intervention. The presented approach also allows sharing of remediation procedures on threat-sharing platforms (e.g. MISP) which improves the overall security posture. The effectiveness of the approach has been tested in the context of two EC-funded projects. Francesco Settanni, Leonardo Regano, Cataldo Basile, Antonio Lioy |
NetSoft | 2 |
| 2023 | Design, implementation, and automation of a risk management approach for man-at-the-End software protectionabstractThe last years have seen an increase in Man-at-the-End (MATE) attacks against software applications, both in number and severity. However, software protection, which aims at mitigating MATE attacks, is dominated by fuzzy concepts and security-through-obscurity. This paper presents a rationale for adopting and standardizing the protection of software as a risk management process according to the NIST SP800-39 approach. We examine the relevant constructs, models, and methods needed for formalizing and automating the activities in this process in the context of MATE software protection. We highlight the open issues that the research community still has to address. We discuss the benefits that such an approach can bring to all stakeholders. In addition, we present a Proof of Concept (PoC) decision support system that instantiates many of the discussed construct, models, and methods and automates many activities in the risk analysis methodology for the protection of software. Despite being a prototype, the PoC’s validation with industry experts indicated that several aspects of the proposed risk management process can already be formalized and automated with our existing toolbox and that it can actually assist decision making in industrially relevant settings. Cataldo Basile, Bjorn De Sutter, Daniele Canavese, Leonardo Regano, Bart Coppens 0001 |
Comput. Secur. | 4 |
| 2022 | A model of capabilities of Network Security FunctionsabstractThis paper presents a formal model of the features, named security capabilities, offered by the controls used for enforcing security policies in computer networks. It has been designed to support policy refinement and policy translation and address useful, practical tasks in a vendor-independent manner. The model adopts state-of-the-art design patterns and has been designed to be extensible. The model describes the actions that the controls can perform (e.g. deny packets or encrypt flows), the conditions to select on what to apply the actions, how to compose valid configuration rules from them, and how to build configurations from rules. It proved effective to model filtering controls and iptables. Cataldo Basile, Daniele Canavese, Leonardo Regano, Ignazio Pedone, Antonio Lioy |
NetSoft | 3 |
| 2020 | Empirical assessment of the effort needed to attack programs protected with client/server code splitting
Alessio Viticchié, Leonardo Regano, Cataldo Basile, Marco Torchiano, Mariano Ceccato, Paolo Tonella |
Empir. Softw. Eng. | 2 |
| 2019 | A meta-model for software protections and reverse engineering attacks
Cataldo Basile, Daniele Canavese, Leonardo Regano, Paolo Falcarin, Bjorn De Sutter |
J. Syst. Softw. | 3 |
| 2017 | Towards Optimally Hiding Protected Assets in Software ApplicationsabstractSoftware applications contain valuable assets that, if compromised, can make the security of users at stake and cause huge monetary losses for software developers. Software protections are applied whenever assets' security is at risk as they delay successful attacks. Unfortunately, protections might have recognizable fingerprints that can expose the location of the assets, thus facilitating the attackers' job. This paper presents a novel approach that uses three main methods to hide the protected assets: protection fingerprint replication, enlargement, and shadowing. The best way to hide assets is determined with a Mixed Integer Linear Program, which is automatically built starting from the code structure, the protected assets, and a model that depicts the dependencies among protection and the fingerprints they generate. Additional constraints, such as overhead limits are also supported to ensure the usability of the protected applications. Our implementation, which uses off-the-shelf solvers, showed promising performance and scalability on large applications. Leonardo Regano, Daniele Canavese, Cataldo Basile, Antonio Lioy |
QRS | 1 |
| 2016 | Assessment of Source Code Obfuscation TechniquesabstractObfuscation techniques are a general category of software protections widely adopted to prevent malicious tampering of the code by making applications more difficult to understand and thus harder to modify. Obfuscation techniques are divided in code and data obfuscation, depending on the protected asset. While preliminary empirical studies have been conducted to determine the impact of code obfuscation, our work aims at assessing the effectiveness and efficiency in preventing attacks of a specific data obfuscation technique - VarMerge. We conducted an experiment with student participants performing two attack tasks on clear and obfuscated versions of two applications written in C. The experiment showed a significant effect of data obfuscation on both the time required to complete and the successful attack efficiency. An application with VarMerge reduces by six times the number of successful attacks per unit of time. This outcome provides a practical clue that can be used when applying software protections based on data obfuscation. Alessio Viticchié, Leonardo Regano, Marco Torchiano, Cataldo Basile, Mariano Ceccato, Paolo Tonella, Roberto Tiella |
SCAM | 2 |
| 2016 | Towards Automatic Risk Analysis and Mitigation of Software Applications
Leonardo Regano, Daniele Canavese, Cataldo Basile, Alessio Viticchié, Antonio Lioy |
WISTP | 1 |