Marco Zuppelli

dblp:272/6591 · DBLP profile ↗
← Back
16ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0001-6932-3199ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 6 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A deep learning-based approach for stegomalware sanitization in digital images
abstract
Abstract Malware is increasingly endowed with steganographic mechanisms for concealing malicious data to avoid detection or bypass security measures. As a result, an emerging wave of threats named stegomalware has started to rise. Among the various approaches, real-world stegomalware primarily hides information within digital images, for instance, to retrieve additional payloads or configuration data. Unfortunately, developing attack-agnostic mitigation tools is difficult, especially due to the tight relation between the image format and the steganographic technique. Therefore, this paper presents an autoencoder-based approach to perform sanitization , i.e., to disrupt the malicious content hidden in images without altering their visual quality. For this purpose, we used an enhanced U-Net-like neural architecture, and we compared our idea against other mechanisms, including JPG transcoding and simple addition of Gaussian noise. Results obtained by considering different hiding patterns and realistic payloads showcased the effectiveness of our approach. Moreover, the U-Net-based sanitization solution prevents the recovery of the payload while preserving the original image quality and reducing risks arising from side-channel attacks.
Angelica Liguori, Marco Zuppelli, Daniela Gallo, Massimo Guarascio 0001, Luca Caviglione
J. Intell. Inf. Syst.2
2024 Investigating HTTP Covert Channels Through Fuzz Testing
abstract
Modern malware increasingly deploys network covert channels to prevent detection or bypass firewalls. Unfortunately, the early discovery of protocol fields and functional behaviors of traffic that can be abused to conceal information is very challenging. In this perspective, fuzz testing could help to face the tight relationship between the used hiding scheme and the targeted protocol trait. Even if fuzzing is a well-established practice to reveal implementation issues, bugs, or unhandled behaviors, it has never been considered to assess the “susceptilibility” of protocols to covert communications.
Kai Hölk, Wojciech Mazurczyk, Marco Zuppelli, Luca Caviglione
ARES3
2024 No Country for Leaking Containers: Detecting Exfiltration of Secrets Through AI and Syscalls
abstract
Containers offer lightweight execution environments for implementing microservices or cloud-native applications. Owing to their ubiquitous diffusion jointly with the complex interplay of hardware, computing, and network resources, effectively enforcing container security is a difficult task. Specifically, runtime detection of threats poses many challenges since container images are often immutable, and many malware deploys obfuscation or elusive mechanisms. Therefore, in this work, we propose a deep-learning-based approach for identifying the presence of two containers colluding to covertly leak secret information. In more detail, we consider a threat actor trying to exfiltrate a 4,096-bit private TLS key via five different covert channels. To decide whether containers are colluding for leaking data, the deep learning model is fed with statistical indicators of the syscalls, which are built starting from simple counters. Results indicate the effectiveness of our approach, even if some adjustments are needed to reduce the number of false positives.
Marco Zuppelli, Massimo Guarascio 0001, Luca Caviglione, Angelica Liguori
ARES1
2024 Erasing the Shadow: Sanitization of Images with Malicious Payloads Using Deep Autoencoders
Angelica Liguori, Marco Zuppelli, Daniela Gallo, Massimo Guarascio 0001, Luca Caviglione
ISMIS2
2024 Mitigation of Covert Communications in MQTT Topics Through Small Language Models
abstract
Modern IoT ecosystems face many security issues. An aspect often neglected concerns covert channels, which allow for exfiltrating data or preventing detection. To this aim, the Message Queuing Telemetry Transport (MQTT) protocol can be abused to create various hidden communication paths, mainly due to its textual nature. Alas, simpler detection metrics could be ineffective and their optimization requires a vast number of test cases. Therefore, this paper proposes to use a small language model trained over real MQTT topics to automatically generate the required test cases. Results indicate the need for optimizations to make popular detection metrics usable “in the wild”.
Camilla Cespi Polisiani, Marco Zuppelli, Mariacarla Calzarossa, Luca Caviglione, Massimo Guarascio 0001
MASCOTS2
2024 Learning autoencoder ensembles for detecting malware hidden communications in IoT ecosystems
abstract
Abstract Modern IoT ecosystems are the preferred target of threat actors wanting to incorporate resource-constrained devices within a botnet or leak sensitive information. A major research effort is then devoted to create countermeasures for mitigating attacks, for instance, hardware-level verification mechanisms or effective network intrusion detection frameworks. Unfortunately, advanced malware is often endowed with the ability of cloaking communications within network traffic, e.g., to orchestrate compromised IoT nodes or exfiltrate data without being noticed. Therefore, this paper showcases how different autoencoder-based architectures can spot the presence of malicious communications hidden in conversations, especially in the TTL of IPv4 traffic. To conduct tests, this work considers IoT traffic traces gathered in a real setting and the presence of an attacker deploying two hiding schemes (i.e., naive and “elusive” approaches). Collected results showcase the effectiveness of our method as well as the feasibility of deploying autoencoders in production-quality IoT settings.
Nunzio Cassavia, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Marco Zuppelli
J. Intell. Inf. Syst.5
2023 Information Leakages of Docker Containers: Characterization and Mitigation Strategies
abstract
Compared to classic virtual machines, containers offer lightweight and dynamic execution environments. Hence, they are core building blocks for the development of future softwarized networks and cloud-native applications. However, containers still pose many security challenges, which are less understood compared to other virtualization paradigms. An important aspect often neglected concerns techniques enabling containers to leak data outside their execution perimeters, e.g., to exfiltrate sensitive information or coordinate attacks. In this paper we investigate security impacts of covert communications based on the looser isolation of memory statistics information. Our characterization indicates that the investigation of system calls should be considered a prime tool to reveal the presence of collusive attack schemes. We also elaborate on two mitigation techniques: the first entails prevention via “hardening” configurations of containers, while the second implements a run-time disruption mechanism.
Marco Zuppelli, Matteo Repetto, Luca Caviglione, Enrico Cambiaso
NetSoft1
2022 Detection of Malicious Images in Production-Quality Scenarios with the SIMARGL Toolkit
abstract
An increasing trend exploits steganography to conceal payloads in digital images, e.g., to drop malicious executables or to retrieve configuration files. Due to the very attack-specific nature of the exploited hiding mechanisms, developing general detection methods is a hard task. An effective approach concerns the creation of ad-hoc solutions to be integrated within general toolkits, also to holistically face unknown threats. Therefore, this paper discusses the integration of a tool for detecting malicious contents hidden in digital images via the Invoke-PSImage technique within the Secure Intelligent Methods for Advanced Recognition of Malware and Stegomalware framework. Since the real impact of images embedding steganographic threats and the behavior of ad-hoc solutions in realistic scenarios are still unknown territories, this work also showcases a performance evaluation conducted in a nation-wide telecommunication provider. Results demonstrated the effectiveness of the approach and also support the need of modular architectures to face the emerging wave of highly-specialized threats.
Luca Caviglione, Martin Grabowski, Kai Gutberlet, Adrian Marzecki, Marco Zuppelli, Andreas Schaffhauser, Wojciech Mazurczyk
ARES5
2022 Revealing MageCart-like Threats in Favicons via Artificial Intelligence
abstract
Modern malware increasingly takes advantage of information hiding to avoid detection, spread infections, and obfuscate code. A major offensive strategy exploits steganography to conceal scripts or URLs, which can be used to steal credentials or retrieve additional payloads. A recent example is the attack campaign against the Magento e-commerce platform, where a web skimmer has been cloaked in favicons to steal payment information of users.
Massimo Guarascio 0001, Marco Zuppelli, Nunzio Cassavia, Luca Caviglione, Giuseppe Manco 0001
ARES2
2022 Ensembling Sparse Autoencoders for Network Covert Channel Detection in IoT Ecosystems
Nunzio Cassavia, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Marco Zuppelli
ISMIS5
2022 Code Layering for the Detection of Network Covert Channels in Agentless Systems
abstract
The growing interest in agentless and serverless environments for the implementation of virtual/container network functions makes monitoring and inspection of network services challenging tasks. A major requirement concerns the agility of deploying security agents at runtime, especially to effectively address emerging and advanced attack patterns. This work investigates a framework leveraging the extended Berkeley Packet Filter to create ad-hoc security layers in virtualized architectures without the need of embedding additional agents. To prove the effectiveness of the approach, we focus on the detection of network covert channels, i.e., hidden/parasitic network conversations difficult to spot with legacy mechanisms. Experimental results demonstrate that different types of covert channels can be revealed with a good accuracy while using limited resources compared to existing cybersecurity tools (i.e., Zeek and libpcap).
Marco Zuppelli, Matteo Repetto, Andreas Schaffhauser, Wojciech Mazurczyk, Luca Caviglione
IEEE Trans. Netw. Serv. Manag.1
2021 bccstego: A Framework for Investigating Network Covert Channels
abstract
Modern malware increasingly exploits information hiding to remain undetected while attacking. To this aim, network covert channels, i.e., hidden communication paths established within legitimate flows, can be used to exfiltrate data or exchange commands without getting noticed by firewalls, antivirus, and intrusion detection systems. Since the secret data can be directly injected in various portions of the stream or encoded via suitable alterations of the traffic, spotting hidden communications is a challenging and poorly generalizable task. Moreover, the majority of works addressed IPv4, thus leaving the detection of covert channels targeting IPv6 almost unexplored.
Matteo Repetto, Luca Caviglione, Marco Zuppelli
ARES3
2021 pcapStego: A Tool for Generating Traffic Traces for Experimenting with Network Covert Channels
abstract
The increasing diffusion of malware endowed with steganographic and cloaking capabilities requires tools and techniques for conducting research activities, testing real deployments and elaborating mitigation mechanisms. To investigate attacks targeting network and appliances, a core requirement concerns the availability of suitable traffic traces, which can be used to derive mathematical models for simulation or to develop machine-learning-based countermeasures. Unfortunately, the young nature of threats injecting secrets or cloaking their presence within network traffic, the high protocol-dependent nature of the various embedding processes, and privacy issues, prevent the vast diffusion of datasets to perform research. Therefore, in this paper we present pcapStego, a tool for creating network covert channels within .pcap files. This approach has two major advantages: it allows to prepare large datasets starting from real network traces, and it generates “replayable” conversations useful for both emulating attacks or conduct pentesting campaigns. To prove the effectiveness of the tool, we showcase the generation of network covert channels targeting IPv6 traffic, which is gaining momentum and it is expected to be a major target for future attacks.
Marco Zuppelli, Luca Caviglione
ARES1
2021 Code Augmentation for Detecting Covert Channels Targeting the IPv6 Flow Label
abstract
Information hiding is at the basis of a new-wave of malware able to elude common detection mechanisms or remain unnoticed for long periods. To this aim, a key approach exploits network covert channels, i.e., abusive communication paths nested within a legitimate traffic flow. The increasing diffusion of IPv6 makes it attractive for an attacker, especially for the presence of the Flow Label field, which can be manipulated to contain up to 20 secret bits per packet. Unfortunately, gathering data to implement a standalone detection mechanism or to support third-party security tools is a poorly generalizable process and often leads to scalability issues. This paper showcases how to take advantage of code augmentation features (i.e., the extended Berkeley Packet Filter) to detect covert channels targeting the IPv6 Flow Label. To prove its effectiveness, the proposed approach has been tested against Internet-wide traffic traces collected in the wild. Results indicate that it is possible to spot the channel while mitigating the memory footprint and the computational burden (e.g., the processed traffic only experience an additional delay of a few nanoseconds).
Luca Caviglione, Marco Zuppelli, Wojciech Mazurczyk, Andreas Schaffhauser, Matteo Repetto
NetSoft2
2021 Kernel-level tracing for detecting stegomalware and covert channels in Linux environments
abstract
Modern malware is becoming hard to spot since attackers are increasingly adopting new techniques to elude signature- and rule-based detection mechanisms. Among the others, steganography and information hiding can be used to bypass security frameworks searching for suspicious communications between processes or exfiltration attempts through covert channels. Since the array of potential carriers is very large (e.g., information can be hidden in hardware resources, various multimedia files or network flows), detecting this class of threats is a scarcely generalizable process and gathering multiple behavioral information is time-consuming, lacks scalability, and could lead to performance degradation. In this paper, we leverage the extended Berkeley Packet Filter (eBPF), which is a recent code augmentation feature provided by the Linux kernel, for programmatically tracing and monitoring the behavior of software processes in a very efficient way. To prove the flexibility of the approach, we investigate two realistic use cases implementing different attack mechanisms, i.e., two processes colluding via the alteration of the file system and hidden network communication attempts nested within IPv6 traffic flows. Our results show that even simple eBPF programs can provide useful data for the detection of anomalies, with a minimal overhead. Furthermore, the flexibility to develop and run such programs allows to extract relevant features that could be used for the creation of datasets for feeding security frameworks exploiting AI.
Luca Caviglione, Wojciech Mazurczyk, Matteo Repetto, Andreas Schaffhauser, Marco Zuppelli
Comput. Networks5
2020 Programmable Data Gathering for Detecting Stegomalware
abstract
The “arm race” against malware developers requires to collect a wide variety of performance measurements, for instance to face threats leveraging information hiding and steganography. Unfortunately, this process could be time-consuming, lack of scalability and cause performance degradations within computing and network nodes. Moreover, since the detection of steganographic threats is poorly generalizable, being able to collect attack-independent indicators is of prime importance. To this aim, the paper proposes to take advantage of the extended Berkeley Packet Filter to gather data for detecting stegomalware. To prove the effectiveness of the approach, it also reports some preliminary experimental results obtained as the joint outcome of two H2020 Projects, namely ASTRID and SIMARGL.
Alessandro Carrega, Luca Caviglione, Matteo Repetto, Marco Zuppelli
NetSoft4