EDBT 2026 Demo / reviewers in the wild / expert
Simone Melloni
dblp:191/0892
· DBLP profile ↗
6ranked-venue papers
0as first author
6since 2021 · last 2026
0000-0002-9535-8747ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SAFARI: A Scalable Air-gapped Framework for Automated Ransomware Investigation
Tommaso Compagnucci, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini |
Comput. Secur. | 4 |
| 2025 | SAFARI: A Scalable Air-Gapped Framework for Automated Ransomware InvestigationabstractRansomware poses a significant threat to individuals and organisations, creating a need for tools to investigate its behaviour and the effectiveness of mitigations. To address this need, we present SAFARI, an open-source framework designed for safe and efficient ransomware analysis. SAFARI’s design emphasises scalability, air-gapped security, and automation, democratising access to safe ransomware investigation tools and fostering collaborative efforts. SAFARI leverages virtualisation, Infrastructure-as-Code, and OS-agnostic task automation to create isolated environments for controlled ransomware execution and analysis. The framework enables researchers to profile ransomware behaviour and evaluate mitigation strategies through automated, reproducible experiments. We demonstrate SAFARI’s capabilities by building a proof-of-concept implementation and using it to conduct two case studies: the first analyses seven ransomware strains – including WannaCry and LockBit – to identify their encryption patterns and file-targeting strategies; the second evaluates Ranflood, a countermeasure tool, against five dangerous strains. Our results provide insights into ransomware behaviour and the effectiveness of countermeasures, showcasing SAFARI’s potential to advance ransomware research and defence development. Tommaso Compagnucci, Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Alessandro Vannini |
SEC (1) | 5 |
| 2025 | Contrasting Crypto and Exfiltration Ransomware with Shamir's Secret Sharing Data FloodingabstractRansomware poses a significant threat to both Individuals and organizations, with crypto-ransomware and exfiltration attacks causing widespread damage, financial loss, and operational disruption. Ranflood is a ransomware attack mitigation tool that confuses and overwhelms attackers by flooding the system with decoy files, thereby slowing down the attack and providing a critical window for intervention. In this paper, we extend the coverage provided by Ranflood with a new, advanced flooding strategy based on Shamir’s Secret Sharing (SSS) to counteract both crypto-and exfiltration ransomware. Our SSS-based strategy confounds ransomware by generating many shards from each user’s file, which we tune for high resilience when contrasting crypto-ransomware (so that the user can regain access to lost data from a few shards) and secrecy against exfiltration (so that the attacker needs many shards to recover the victim’s data). We explore the theoretical and practical challenges of applying SSS in this context, present the design and implementation details of our flooder, and empirically evaluate and profile its performance. Daniele D'Ugo, Saverio Giallorenzo, Simone Melloni |
TrustCom | 3 |
| 2025 | Reliable and Robust Watermarking for Data Flooding against Ransomware Random TechniquesabstractData Flooding Against Ransomware (DFaR) techniques combat ransomware through decoy files that can reveal a ransomware’s activity and reduce the effectiveness and efficiency of attacks by confounding legitimate user files and competing for IO resource access of the attacked host. While effective, existing DFaR random strategies (which flood a user system with realistic yet random-content decoy files) face challenges during restoration, due to the necessity of pre-attack file lists to discriminate between proper and decoy files (the latter should be removed to restore the system to its pre-attack state). To tackle this issue, we present a watermarking-based approach that embeds imperceptible watermarks in random-content decoy files. Our technique preserves the indistinguishability of decoys from user files to attackers, while providing users with a reliable mechanism to differentiate between authentic and decoy content, obviating the need for pre-attack file lists. We present experimental evaluations that demonstrate that our watermarking technique a) imposes minimal-to-medium computational overhead (depending on user-configurable parameters) compared to existing random-content flooding methods (i.e., it is efficient when contrasting ransomware and restoring a user’s system) and b) it provides strong resistance against adversarial inference attacks. Saverio Giallorenzo, Simone Melloni, Pietro Sami |
TrustCom | 2 |
| 2025 | Investigating operational technology attacks as codeabstractAbstract Industrial Operational Technology (OT) environments face escalating cybersecurity challenges due to increasing interconnectedness, device heterogeneity, and the integration of legacy systems not designed with modern security requirements. Operators struggle with security validation in OT settings due to the complexity of static reasoning across multilayered architectures and the impracticality of in-production testing, which risks operational disruptions and safety hazards. To address these limitations, we propose SAFARI, a framework that leverages the concepts of digital twin and cyber range to enable Security-Investigation-as-Code for OT environments, automating the creation, deployment, and security testing of faithful OT architecture replicas. SAFARI uses technologies such as Terraform, Proxmox SDN, and MITRE Caldera to provide scalable, reproducible security assessment capabilities while maintaining complete air-gapping for safe malware testing. We demonstrate SAFARI’s effectiveness through a comprehensive case study examining three industrial network architectures exhibiting increasing segmentation. Our results show that SAFARI successfully automates complex security scenarios, enables regression testing of architectural refinements, and provides quantifiable insights into attack resistance improvements. The framework represents a significant advancement in OT security testing methodology, offering security operators a practical tool for systematic vulnerability assessment and architectural validation without compromising operational continuity. Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini |
Empir. Softw. Eng. | 4 |
| 2023 | Data Flooding against Ransomware: Concepts and ImplementationsabstractRansomware is one of the most infamous kinds of malware, particularly the “crypto” subclass, which encrypts users’ files, asking for some monetary ransom in exchange for the decryption key. Recently, crypto-ransomware grew into a scourge for enterprises and governmental institutions. The most recent and impactful cases include an oil company in the US, an international Danish shipping company, and many hospitals and health departments in Europe. Attacks result in production lockdowns, shipping delays, and even risks to human lives. To contrast ransomware attacks (crypto, in particular), we propose a family of solutions, called Data Flooding against Ransomware, tackling the main phases of detection, mitigation, and restoration, based on a mix of honeypots, resource contention, and moving target defence. These solutions hinge on detecting and contrasting the action of ransomware by flooding specific locations (e.g., the attack location, sensible folders, etc.) of the victim’s disk with files. Besides the abstract definition of this family of solutions, we present an open-source tool that implements the mitigation and restoration phases, called Ranflood. In particular, Ranflood supports three flooding strategies, apt for different attack scenarios. At its core, Ranflood buys time for the user to counteract the attack, e.g., to access an unresponsive, attacked server and shut it down manually. We benchmark the efficacy of Ranflood by performing a thorough evaluation over 6 crypto-ransomware (e.g., WannaCry, LockBit) for a total of 78 different attack scenarios, showing that Ranflood consistently lowers the amount of files lost to encryption. Davide Berardi, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Loris Onori, Marco Prandini |
Comput. Secur. | 4 |