EDBT 2026 Demo / reviewers in the wild / expert
Daniel Ricardo dos Santos
dblp:201/0224
· DBLP profile ↗
20ranked-venue papers
7as first author
4since 2021 · last 2024
0000-0002-7747-260XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 4 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Using DNS Patterns for Automated Cyber Threat AttributionabstractLinking attacks to the actors responsible is a critical part of threat analysis. Threat attribution, however, is challenging. Attackers try to avoid detection and avert attention to mislead investigations. The trend of attackers using malicious services provided by third parties also makes it difficult to discern between attackers and providers. Besides that, having a security team doing manual-only analysis might overwhelm analysts. As a result, the effective use of any trustworthy information for attribution is paramount, and automating this process is valuable. For this purpose, we propose an approach to perform automated attribution with a source of reliable information currently underutilised, the DNS patterns used by attackers. Our method creates recommendations based on similar patterns observed between a new incident and already attributed attacks and then generates a list of the most similar attacks. We show that our approach can, at ten recommendations, achieve 0.8438 precision and 0.7378 accuracy. We also show that DNS patterns have a short lifespan, allowing their utility even in more recent knowledge bases. Cristoffer Leite, Jerry den Hartog, Daniel Ricardo dos Santos |
ARES | 3 |
| 2024 | Poster: A Multi-step Approach for Classification of Malware SamplesabstractThe rapid spread of unknown malware has prompted many companies and researchers to improve their detection and classification systems. Cyber security companies must deal with the newest malware samples captured by their honeypots, aiming to analyze and classify them to develop several countermeasures. This process could only be feasible with a strong ground truth baseline; companies could only securely store the samples, waiting for further developments. This paper proposes a multi-step approach to support the classification process of unknown malware samples. Specifically, our approach first leverages well-known classification techniques and third-party services to collect as much information as possible about the samples and combines them with Machine Learning (ML)-based techniques to classify the remaining samples. Our case study, conducted on industrial data, shows how the combination offers superior performance than using each method individually. Arnaldo Sgueglia, Rocco Addabbo, Andrea Di Sorbo, Stanislav Dashevskyi, Daniel Ricardo dos Santos, Corrado Aaron Visaggio |
CCS | 5 |
| 2023 | Automated Cyber Threat Intelligence Generation on Multi-Host Network IncidentsabstractThe lack of automation is one of the main issues hindering the broad usage of high-level Cyber Threat Intelligence (CTI). Creating and using such information by capturing Tactics, Techniques and Procedures (TTPs) is currently an arduous manual task for Cyber Security Incident Response Teams (CSIRT). For CSIRTs, a Network Intrusion Detection System (NIDS) automates the detection of cyber threats. It provides relevant information about alerts to the analysts. This information could generate CTI reports to help others better protect themselves from similar attacks. Due to the demanding work involved in manually creating high-level CTI reports for multi-host incidents, automating this process has become increasingly important.In this paper, a solution is presented to automate the creation of verifiable high-level cyber threat intelligence reports by mapping chains of alerts to TTPs. The solution enables visualisation of attack chains and tactics used, but also manual analysis and validation of the reports created. The proposed approach is evaluated by comparing generating reports with existing CTI, validating any additional TTPs found. The evaluation shows that, not only it was able to match existing reports, but it was also able to improve the knowledge about these threats. Cristoffer Leite, Jerry den Hartog, Daniel Ricardo dos Santos, Elisa Costante |
IEEE Big Data | 3 |
| 2023 | Access Control Vulnerabilities in Network Protocol Implementations: How Attackers Exploit Them and What To Do About ItabstractAuthentication and access control mechanisms should verify the identity of users of a system and ensure that these users only act within their intended permissions. These mechanisms, alongside audit or intrusion detection, have been called the "foundation for information and system security'' [8]. There has been a large amount of research proposing authentication and authorization mechanisms for network protocols and devices used in Operational Technology (OT) and the Internet of Things (IoT) [7]. Although these devices run our critical infrastructure, most of them still rely on simple password-based mechanisms to prevent unauthorized operations [1]. More worryingly, even these simple mechanisms often have flawed implementations, allowing malicious actors to bypass them [6]. Daniel Ricardo dos Santos |
SACMAT | 1 |
| 2020 | Security and Privacy in Smart Grids: Challenges, Current Solutions and Future OpportunitiesabstractSmart grids are a promising upgrade to legacy power grids due to enhanced cooperation of involved parties, such as consumers and utility providers. These newer grids improve the efficiency of electricity generation and distribution by leveraging communication networks to exchange information between those different parties. However, the increased connection and communication also expose the control networks of the power grid to the possibility of cyber-attacks. Therefore, research on cybersecurity for smart grids is crucial to ensure the safe operation of the power grid and to protect the privacy of consumers. In this paper, we investigate the security and privacy challenges of the smart grid; present current solutions to these challenges, especially in the light of intrusion detection systems; and discuss how future grids will create new opportunities for cybersecurity. Ismail Butun, Alexios Lekidis, Daniel Ricardo dos Santos |
ICISSP | 3 |
| 2020 | A Matter of Life and Death: Analyzing the Security of Healthcare Networks
Guillaume Dupont, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle |
SEC | 2 |
| 2019 | Role Inference + Anomaly Detection = Situational Awareness in BACnet Networks
Davide Fauri, Michail Kapsalakis, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle |
DIMVA | 3 |
| 2019 | TestREx: a framework for repeatable exploits
Stanislav Dashevskyi, Daniel Ricardo dos Santos, Fabio Massacci, Antonino Sabetta |
Int. J. Softw. Tools Technol. Transf. | 2 |
| 2018 | Leveraging Semantics for Actionable Intrusion Detection in Building Automation Systems
Davide Fauri, Michail Kapsalakis, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle |
CRITIS | 3 |
| 2018 | Solving Multi-Objective Workflow Satisfiability Problems with Optimization Modulo Theories TechniquesabstractSecurity-sensitive workflows impose constraints on the controlflow and authorization policies that may lead to unsatisfiable instances. In these cases, it is still possible to find "least bad" executions where costs associated to authorization violations are minimized, solving the so-called Multi-Objective Workflow Satisfiability Problem (MO-WSP). The MO-WSP is inspired by the Valued WSP and its generalization, the Bi-Objective WSP, but our work considers quantitative solutions to the WSP without abstracting control-flow constraints. In this paper, we define variations of the MO-WSP and solve them using bounded model checking and optimization modulo theories solving. We validate our solutions on real-world workflows and show their scalability on synthetic instances. Clara Bertolissi, Daniel Ricardo dos Santos, Silvio Ranise |
SACMAT | 2 |
| 2017 | Aegis: Automatic Enforcement of Security Policies in Workflow-driven Web ApplicationsabstractOrganizations often expose business processes and services as web applications. Improper enforcement of security policies in these applications leads to business logic vulnerabilities that are hard to find and may have dramatic security implications. Aegis is a tool to automatically synthesize run-time monitors to enforce control-flow and data-flow integrity, as well as authorization policies and constraints in web applications. The enforcement of these properties can mitigate attacks, e.g., authorization bypass and workflow violations, while allowing regulatory compliance in the form of, e.g., Separation of Duty. Aegis is capable of guaranteeing business continuity while enforcing the security policies. We evaluate Aegis on a set of real-world applications, assessing the enforcement of policies, mitigation of vulnerabilities, and performance overhead. Luca Compagna, Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
CODASPY | 2 |
| 2017 | On Run-Time Enforcement of Authorization Constraints in Security-Sensitive Workflows
Daniel Ricardo dos Santos, Silvio Ranise |
SEFM | 1 |
| 2017 | Automatically finding execution scenarios to deploy security-sensitive workflowsabstractWe introduce a new class of analysis problems, called Scenario Finding Problems (SFPs), for security-sensitive business processes that – besides execution constraints on tasks – define access control policies (constraining which users can execute which tasks) and authorization constraints (such as Separation of Duty). The solutions to SFPs are concrete execution scenarios that assist customers in the reuse and deployment of security-sensitive workflows. We study the relationship of SFPs to well-known properties of security-sensitive processes such as Workflow Satisfiability and Resiliency together with their complexity. Finally, we present a symbolic approach to solving SFPs and describe our experience with a prototype implementation on real-world business process models taken from an on-line library. Daniel Ricardo dos Santos, Silvio Ranise, Luca Compagna, Serena Elisa Ponta |
J. Comput. Secur. | 1 |
| 2016 | Modular Synthesis of Enforcement Mechanisms for the Workflow Satisfiability Problem: Scalability and ReusabilityabstractModularity is an important concept in the design and enactment of workflows. However, supporting the specification and enforcement of authorization in this setting is not straightforward. In this paper, we introduce a notion of component and a combination mechanism for security-sensitive workflows. These are business processes in which execution constraints on the tasks are complemented with authorization constraints (e.g., Separation of Duty) and authorization policies (specifying which users can execute which tasks). We show how authorization constraints can also be imposed across components and demonstrate the usefulness of our notion of component by showing (i) the scalability of a technique for the synthesis of run-time monitors for security-sensitive workflows; and (ii) the design of a plug-in for the reuse of workflows and related run-time monitors inside an editor for security-sensitive workflows. Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
SACMAT | 1 |
| 2016 | Cerberus: Automated Synthesis of Enforcement Mechanisms for Security-Sensitive Business Processes
Luca Compagna, Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
TACAS | 2 |
| 2016 | A framework and risk assessment approaches for risk-based access control in the cloud
Daniel Ricardo dos Santos, Roberto Marinho, Gustavo Roecker Schmitt, Carla Merkle Westphall, Carlos Becker Westphall |
J. Netw. Comput. Appl. | 1 |
| 2015 | Automated Synthesis of Run-time Monitors to Enforce Authorization Policies in Business ProcessesabstractRun-time monitors are crucial to the development of security-aware workflow management systems, which need to mediate access to their resources by enforcing authorization policies and constraints, such as Separation of Duty. In this paper, we introduce a precise technique to synthesize run-time monitors capable of ensuring the successful termination of workflows while enforcing authorization policies and constraints. An extensive experimental evaluation shows the scalability of our technique on the important class of hierarchically specified security-sensitive workflows with several hundreds of tasks. Clara Bertolissi, Daniel Ricardo dos Santos, Silvio Ranise |
AsiaCCS | 2 |
| 2015 | Assisting the Deployment of Security-Sensitive Workflows by Finding Execution Scenarios
Daniel Ricardo dos Santos, Silvio Ranise, Luca Compagna, Serena Elisa Ponta |
DBSec | 1 |
| 2014 | A dynamic risk-based access control architecture for cloud computingabstractCloud computing is a distributed computing model that still faces problems. New ideas emerge to take advantage of its features and among the research challenges found in the cloud, we can highlight Identity and Access Management. The main problems of the application of access control in the cloud are the necessary flexibility and scalability to support a large number of users and resources in a dynamic and heterogeneous environment, with collaboration and information sharing needs. This paper proposes the use of risk-based dynamic access control for cloud computing. The proposal is presented as an access control model based on an extension of the XACML standard with three new components: the Risk Engine, the Risk Quantification Web Services and the Risk Policies. The risk policies present a method to describe risk metrics and their quantification, using local or remote functions. The risk policies allow users and cloud service providers to define how to handle risk-based access control for their resources, using different quantification and aggregation methods. The model reaches the access decision based on a combination of XACML decisions and risk analysis. A prototype of the model is implemented, showing it has enough expressivity to describe the models of related work. In the experimental results, the prototype takes between 2 and 6 milliseconds to reach access decisions using a risk policy. A discussion on the security aspects of the model is also presented. Daniel Ricardo dos Santos, Carla Merkle Westphall, Carlos Becker Westphall |
NOMS | 1 |
| 2014 | A cyclical evaluation model of information security maturityabstractPurpose – This paper aims at presenting a cyclical evaluation model of information security (IS) maturity. The lack of a security evaluation method might expose organizations to several risky situations. Design/methodology/approach – This model was developed through the definition of a set of steps to be followed to obtain periodical evaluation of maturity and continuous improvement of controls. Findings – This model, based on controls present in ISO/IEC 27002, provides a means to measure the current situation of IS management through the use of a maturity model and provides a subsidy to take appropriate and feasible improvement actions, based on risks. A case study is performed, and the results indicate that the method is efficient for evaluating the current state of IS, to support IS management, risks identification and business and internal control processes. Research limitations/implications – It is possible that modifications to the process may be needed where there is less understanding of security requirements, such as in a less mature organization. Originality/value – This paper presents a generic model applicable to all kinds of organizations. The main contribution of this paper is the use of a maturity scale allied to the cyclical process of evaluation, providing the generation of immediate indicators for the management of IS. Evandro Alencar Rigon, Carla Merkle Westphall, Daniel Ricardo dos Santos, Carlos Becker Westphall |
Inf. Manag. Comput. Secur. | 3 |