EDBT 2026 Demo / reviewers in the wild / expert
Rosangela Casolare
dblp:259/7264
· DBLP profile ↗
12ranked-venue papers
8as first author
9since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 4 first-author · 4 since 2021Security and privacy · 6 · 4 first-author · 5 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | StegWare: A Novel Malware Model Exploiting Payload Steganography and Dynamic Compilation
Daniele Albanese, Rosangela Casolare, Giovanni Ciaramella, Giacomo Iadarola, Fabio Martinelli, Francesco Mercaldo, Marco Russodivito, Antonella Santone |
ICISSP | 2 |
| 2022 | On the Resilience of Shallow Machine Learning Classification in Image-based Malware DetectionabstractShallow machine learning is massively applied by researchers with the aim to detect (novel and unseen) malicious applications. Machine learning models are typically evaluated using malicious and trusted applications generated over a short period. In the real world, these models aim to identify malware that were not seen previously during the training phase. In this paper, we investigate how well machine learning-based malware detectors can actually detect malware in the real-world environment. By representing an Android application in terms of image, we evaluate the resilience of several popular supervised machine learning algorithms exploited by current literature for the malware detection task. The experimental results demonstrate the poor resilience of the machine learning models used for malware detection. Rosangela Casolare, Giovanni Ciaramella, Giacomo Iadarola, Fabio Martinelli, Francesco Mercaldo, Antonella Santone, Michele Tommasone |
KES | 1 |
| 2022 | A Real-time Method for CAN Bus Intrusion Detection by Means of Supervised Machine Learning
Francesco Mercaldo, Rosangela Casolare, Giovanni Ciaramella, Giacomo Iadarola, Fabio Martinelli, Francesco Ranieri, Antonella Santone |
SECRYPT | 2 |
| 2021 | SteælErgon: A Framework for Injecting Colluding Malicious Payload in Android ApplicationsabstractMobile malware is growing in number and its complexity is constantly increasing. Malware authors are continuously looking new ways to elude anti-malware controls. Anti-malware are not able to detect zero-day malware, because to detect malicious behaviour they need to know its signature, but to have this information the malware must already be widespread. Furthermore, anti-malware are able to scan one application at a time: for this reason a type of malware characterized by the colluding attack, where the malicious action is split in two (or more) applications, can not be recognised. Rosangela Casolare, Giovanni Ciaramella, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
ARES | 1 |
| 2021 | Colluding Covert Channel for Malicious Information Exfiltration in Android Environment
Rosangela Casolare, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
ICISSP | 1 |
| 2021 | A Semi-Automated Explainability-Driven Approach for Malware Analysis through Deep LearningabstractCybercriminals are continually working to develop increasingly aggressive malicious code to steal sensitive and private information from mobile devices. Antimalware are not always able to detect all threats, especially when they do not have previous knowledge of the malware signature. Moreover, malware code analysis remains a time-consuming process for security analysts. In this regard, we propose a method aimed to detect the malware belonging family and automatically pointing out a subset of potentially malicious classes. The rationale behind this work aims (i) to save valuable time for the security analyst by decreasing the amount of code to analyse, and (ii) to improve the interpretability of image-based deep learning model for malware family detection. We represent an application as an image and classify it with a deep learning model aimed to predict the belonging family; then, exploiting the use of activation maps, the approach points out potentially malicious classes to help the security analysts in the malicious behaviour recognition. The proposed method obtains an overall accuracy of 0.944 in the evaluation of a dataset composed of 8430 real-world Android malware, showing also that the use of activation maps can provide explainability about the deep learning model decision. Giacomo Iadarola, Rosangela Casolare, Fabio Martinelli, Francesco Mercaldo, Christian Peluso, Antonella Santone |
IJCNN | 2 |
| 2021 | Android Collusion Detection by means of Audio Signal Analysis with Machine Learning techniquesabstractSmartphones, tablets and other mobile devices have become objects that we can no longer do without, as a matter of fact for us they are like an extension of our body and many people are addicted to them; this behavior is a consequence of the use we make of it, since these devices allow us to manage sensitive data (i.e., financial ones) and access information of different types (i.e., photos, messages or health data). For this reason it is essential to detect the harmful behaviors present within our smartphones, taking into account the weaknesses of the current anti-malware mechanisms. In this article we propose an approach capable of discriminating trusted applications from those that instead have malicious behavior, since they are involved in a colluding attack. We resort to the processing of the audio signal extracted from the conversion of an application into an audio file. The processing allows to generate a vector of characteristics to be analyzed with different classifiers. The experimental analysis is performed on a set of Android applications consisting of 359 trusted and (colluding) untrusted applications, showing the effectiveness of our method in detecting colluding applications. Rosangela Casolare, Umberto Di Giacomo, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
KES | 1 |
| 2021 | Exploiting Supervised Machine Learning for Driver Detection in a Real-World EnvironmentabstractThe proliferation of info-entertainment systems in today’s vehicles has provided a really cheap and easy-to-deploy platform with the ability to gather information about the vehicle under analysis. Ultra-response connectivity networks with a latency below 10 milliseconds are providing the perfect infrastructure in which this information can be sent to improve safety and security. With the purpose of providing an architecture to increase safety and security in an automotive context, we in this paper propose a method for detecting the driver in real-time exploiting supervised machine learning techniques. The experimental analysis performed on real-world data shows that the proposed method obtains encouraging results. Umberto Di Giacomo, Rosangela Casolare, Oliver Eigner, Fabio Martinelli, Francesco Mercaldo, Torsten Priebe, Antonella Santone |
KES | 2 |
| 2021 | Mobile Family Detection through Audio Signals Classification
Rosangela Casolare, Giacomo Iadarola, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
SECRYPT | 1 |
| 2020 | VisualDroid: automatic triage and detection of Android repackaged applicationsabstractConsidering the pervasiveness of mobile devices, malicious writers are constantly focusing their attention in developing malicious payload aimed to gather sensible information from mobile devices without user content. As a matter of fact, it is really easy for malware writers to embed malicious payloads into legitimate applications, by applying the so-called repackaging paradigm, to generate a sample with a signature unknown to anti-malware software. In this paper we propose a twofold approach for the triage and the detection of repackaged Android applications. We propose a visualization schema to assist the malware analyst in the triage of unseen applications and a set of metrics for the automatic detection of repackaged applications. Experimental results show the effectiveness of the proposed approach. Rosangela Casolare, Carlo De Dominicis, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
ARES | 1 |
| 2020 | Malicious Collusion Detection in Mobile Environment by means of Model CheckingabstractEveryday born a new cyberattack and among these an emerging attack is represent by the so-called colluding. The application collusion attack is a new form of threat that is becoming widespread in mobile environment, especially in Android platform. This technique requires that two or more apps cooperate in some way with the aim to perform a malicious action that they are unable to perform independently. Detecting colluding apps is challenging problem, because currently there are no effective tools due to the search space of all possible combination of apps. In this paper we present a method exploiting model checking technique with the aim to detect a collusion attack between two applications. The method uses a heuristic function able to reduce the number of the analyzed apps and to localize the collusion attack. This heuristic function is based on the study of execution flow of an application, to identify the execution flow and verify it. The proposed algorithm verify if there is a flow of sensitive data that ends up in a shared resource and if this happens the app could be marked as potentially collusive, otherwise it is possible to exclude the app from the analysis, in order to reduce the number of apps to be analyzed. Experimental results on a data-set of Android applications show promising performances in colluding mobile app detection. Rosangela Casolare, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
IJCNN | 1 |
| 2019 | A Model Checking based Proposal for Mobile Colluding Attack DetectionabstractThe application collusion attack is a new form of threat that is becoming widespread in mobile environment. This technique requires that two or more apps cooperate in some way with the aim to perform a malicious action that they are unable to perform independently. In this paper we propose the adoption of model checking to detect whether two or more apps are performing a collusion attack. Rosangela Casolare, Fabio Martinelli, Francesco Mercaldo, Antonella Santone |
IEEE BigData | 1 |