EDBT 2026 Demo / reviewers in the wild / expert
Salvatore Manfredi
dblp:244/0589
· DBLP profile ↗
6ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0001-9645-6034ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Comparison of Credential Status Mechanisms for the Digital Wallet Ecosystem
Riccardo Germenia, Salvatore Manfredi, Giada Sciarretta, Mario Scuro, Alessandro Tomasi 0001 |
SECRYPT | 2 |
| 2024 | Automating Compliance for Improving TLS Security Postures: An Assessment of Public Administration Endpoints
Riccardo Germenia, Salvatore Manfredi, Matteo Rizzi, Giada Sciarretta, Alessandro Tomasi 0001, Silvio Ranise |
SECRYPT | 2 |
| 2022 | A Modular and Extensible Framework for Securing TLSabstractWhile being both extremely powerful and popular, TLS is a protocol that is hard to securely deploy. On the one hand, system administrators are required to grasp several security concepts to fully understand the impact of each option and avoid misconfigurations. On the other hand, app developers should use cryptographic libraries in a secure way avoiding dangerous default settings or other subtleties (e.g., padding or modes of operations). To help secure TLS, we propose a modular framework, extensible with new features and capable of streamlining the mitigation process of known and newly discovered TLS attacks even for non-expert users. Matteo Rizzi, Salvatore Manfredi, Giada Sciarretta, Silvio Ranise |
CODASPY | 2 |
| 2022 | Demo: TLSAssistant v2: A Modular and Extensible Framework for Securing TLSabstractTo grasp the security implications of the various TLS configuration options, system administrators and app developers must be familiar with a wide range of concepts, including cryptography. To assist users in this task, we propose TLSAssistant- a modular and extensible framework designed to streamline the discovery and mitigation of potential vulnerabilities in TLS deployments. This demo will focus on two of the four available analysis types. Matteo Rizzi, Salvatore Manfredi, Giada Sciarretta, Silvio Ranise |
SACMAT | 2 |
| 2021 | Do Security Reports Meet Usability?: Lessons Learned from Using Actionable Mitigations for Patching TLS MisconfigurationsabstractSeveral automated tools have been proposed to detect vulnerabilities. These tools are mainly evaluated in terms of their accuracy in detecting vulnerabilities, but the evaluation of their usability is a commonly neglected topic. Usability of automated security tools is particularly crucial when dealing with problems of cryptographic protocols for which even small—apparently insignificant—changes in their configuration can result in vulnerabilities that, if exploited, pave the way to attacks with dramatic consequences for the confidentiality and integrity of exchanged messages. This becomes even more acute when considering such ubiquitous protocols as the one for Transport Layer Security (TLS for short). In this paper, we present the design and the lessons learned of a user study, meant to compare two different approaches when reporting misconfigurations. Results reveal that including contextualized actionable mitigations in security reports significantly impact the accuracy and the time needed to patch TLS vulnerabilities. Along with the lessons learned, we share the experimental material that can be used during cybersecurity labs to let students configure and patch TLS first-hand. Salvatore Manfredi, Mariano Ceccato, Giada Sciarretta, Silvio Ranise |
ARES | 1 |
| 2019 | Lost in TLS? No More! Assisted Deployment of Secure TLS Configurations
Salvatore Manfredi, Silvio Ranise, Giada Sciarretta |
DBSec | 1 |