EDBT 2026 Demo / reviewers in the wild / expert
Mariano Di Martino
dblp:227/0695
· DBLP profile ↗
6ranked-venue papers
4as first author
2since 2021 · last 2022
0000-0002-2848-5252ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Revisiting Identification Issues in GDPR 'Right Of Access' Policies: A Technical and Longitudinal AnalysisabstractAbstract Several data protection regulations permit individuals to request all personal information that an organization holds about them by utilizing Subject Access Requests (SARs). Prior work has observed the identification process of such requests, demonstrating weak policies that are vulnerable to potential data breaches. In this paper, we analyze and compare prior work in terms of methodologies, requested identification credentials and threat models in the context of privacy and cybersecurity. Furthermore, we have devised a longitudinal study in which we examine the impact of responsible disclosures by re-evaluating the SAR authentication processes of 40 organizations after they had two years to improve their policies. Here, we demonstrate that 53% of the previously vulnerable organizations have not corrected their policy and an additional 27% of previously non-vulnerable organizations have potentially weakened their policies instead of improving them, thus leaking sensitive personal information to potential adversaries. To better understand state-of-the-art SAR policies, we interviewed several Data Protection Officers and explored the reasoning behind their processes from a viewpoint in the industry and gained insights about potential criminal abuse of weak SAR policies. Finally, we propose several technical modifications to SAR policies that reduce privacy and security risks of data controllers. Mariano Di Martino, Isaac Meers, Peter Quax, Ken Andries, Wim Lamotte |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | ESQABE: Predicting Encrypted Search Queries
Isaac Meers, Mariano Di Martino, Peter Quax, Wim Lamotte |
SEC | 2 |
| 2020 | Practical operation extraction from electromagnetic leakage for side-channel analysis and reverse engineeringabstractDetermining which operations are being executed by a black-box device is an important challenge to tackle in reverse engineering. Furthermore, in order to perform a successful side-channel analysis (SCA) of said operations, their precise timing must be determined. In this paper, we tackle these two challenges in context of an electromagnetic (EM) analysis of a NodeMCU Amica IoT device. More specifically, we propose a convolutional neural network (CNN) architecture that is designed to classify operations performed by the NodeMCU out of a set of 8 possible operations, namely OpenSSL AES, native AES, TinyAES, OpenSSL DES, SHA1-PRF, HMAC-SHA1, SHA1, and SHA1Transform. In addition, we use the same architecture to predict the start and end times of the operation, thereby removing the need for firmware modifications or manual triggers in SCA. Our approach is evaluated using a 66 GB dataset containing 69,632 complex traces of EM leakage, captured with a USRP B210 software defined radio. The best variant of our methodology achieves a classification accuracy of 96.47%, and is able to predict the start and end times of the operation within 34 |is of the ground truth on average. We compare our methodology to classical template matching, and provide our open-source implementation and datasets to the community so that the achieved results can be reproduced. Pieter Robyns, Mariano Di Martino, Dennis Giese, Wim Lamotte, Peter Quax, Guevara Noubir |
WISEC | 2 |
| 2020 | Knocking on IPs: Identifying HTTPS Websites for Zero-Rated TrafficabstractZero-rating is a technique where internet service providers (ISPs) allow consumers to utilize a specific website without charging their internet data plan. Implementing zero-rating requires an accurate website identification method that is also efficient and reliable to be applied on live network traffic. In this paper, we examine existing website identification methods with the objective of applying zero-rating. Furthermore, we demonstrate the ineffectiveness of these methods against modern encryption protocols such as Encrypted SNI and DNS over HTTPS and therefore show that ISPs are not able to maintain the current zero-rating approaches in the forthcoming future. To address this concern, we present “Open-Knock,” a novel approach that is capable of accurately identifying a zero-rated website, thwarts free-riding attacks, and is sustainable on the increasingly encrypted web. In addition, our approach does not require plaintext protocols or preprocessed fingerprints upfront. Finally, our experimental analysis unveils that we are able to convert each IP address to the correct domain name for each website in the Tranco top 6000 websites list with an accuracy of 50.5% and therefore outperform the current state-of-the-art approaches. Mariano Di Martino, Peter Quax, Wim Lamotte |
Secur. Commun. Networks | 1 |
| 2019 | Realistically Fingerprinting Social Media Webpages in HTTPS TrafficabstractIn webpage fingerprinting (WPF), an adversary attempts to identify webpages in encrypted network traffic. Identifying social media webpages however is a challenging task, due to the similarity and dynamic nature of such pages. Existing webpage fingerprinting attacks often have unrealistic assumptions regarding the capability of government agencies or knowledge of the criminal's environment, which renders these attacks ineffective when applied to social media platforms. In this paper, we unravel the current concerns in state of the art WPF attacks in a social network context for forensic analysis. To resolve the issues presented, we propose an enhanced version of the WPF attack 'IUPTIS' and introduce an intelligent observer that significantly improves upon previous works. Furthermore, our improvements are compared to related WPF attacks by conducting extensive experiments on two social platforms: Twitter and Instagram. Our examination shows that the improved IUPTIS attack defeats previous works in terms of realistic obstacles such as HTTP/2, caching and performance costs, thus making it feasible to identify social media webpages with minimal resources. Mariano Di Martino, Peter Quax, Wim Lamotte |
ARES | 1 |
| 2018 | IUPTIS: A Practical, Cache-resistant Fingerprinting Technique for Dynamic WebpagesabstractWebpage fingerprinting allows an adversary to infer the webpages visited by an end user over an encrypted channel by means of network traffic analysis. If such techniques are applied to websites that contain user profiles (e.g. booking platforms), they can be used for personal identification and pose a clear privacy threat. In this paper, a novel HTTPS webpage fingerprinting method - IUPTIS - is presented, which accomplishes precisely this, through identification and analysis of unique image sequences. It improves upon previous work by being able to fingerprint webpages containing dynamic rather than just static content, making it applicable to e.g. social network pages as well. At the same time, it is not hindered by the presence of caching and does not require knowledge of the specific browser being used. Several accuracy-increasing parameters are integrated that can be tuned according to the specifics of the adversary model and targeted online platform. To quantify the real-world applicability of the IUPTIS method, experiments have been conducted on two popular online platforms. Favorable results were achieved, with a F1 scores between of 82% and 98%, depending on the parameters used. This makes the method practically viable as a means for personal identification. Mariano Di Martino, Pieter Robyns, Peter Quax, Wim Lamotte |
WEBIST | 1 |