Enrico Bassetti

dblp:276/7890 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0003-4804-0311ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Opening Pandora's Packet: Expose IPv6 Implementations Vulnerabilities Using Differential Fuzzing
Enrico Bassetti, Edoardo Di Paolo, Francesco Drago, Mauro Conti, Angelo Spognardi
ACNS (1)1
2025 Have you SYN What I See? Analyzing TCP SYN Payloads in the Wild
abstract
TCP SYN packets are typically meant to initiate a three-way handshake for new connections and do not carry a payload. The only exception, according to the standards, is TCP Fast Open, where data is transmitted as TCP SYN payload.
Dario Ferrero, Enrico Bassetti, Harm Griffioen, Georgios Smaragdakis
IMC2
2025 QUICkly Running Out of Money: Evaluating QUIC Resilience to Traffic Inflating Attacks
abstract
The adoption of the QUIC protocol has significantly improved the performance and security of modern internet applications, mainly due to the central role that encryption plays in the protocol. However, this emerging protocol introduces new vulnerabilities that can be exploited for malicious purposes. This paper investigates the resilience of QUIC to selective traffic manipulation attacks aimed at inflating network traffic, which can lead to increased operational costs for service providers and degraded user experiences.We present three distinct attacks designed to manipulate QUIC traffic by selectively dropping or manipulating packets. One attack can be executed by any middlebox in the network path between the client and the server, while the others require the attacker to have some previous control of QUIC components. Through experimental analysis, we evaluate the impact of these attacks on inflating the packet and data accounting. Our results show that attackers can effectively increase data traffic up to 50% of the original transmission size without altering the content of the QUIC communication. These findings highlight the potential for significant traffic inflation and offer insights into countermeasures that could mitigate the risks posed by these vulnerabilities.
Giovanni Menon, Enrico Bassetti, Mauro Conti
TrustCom2
2024 "They Will Adapt": Improving Anomaly Detection on IoT Networks Through Continuous Learning
abstract
The ubiquitous presence of Internet-of-Things devices represents a menace to cybersecurity since their low computational power does not allow classic countermeasures techniques. In recent years, anomaly detection using Machine Learning has acquired popularity among researchers; however, current datasets in literature are sub-optimal, making exhaustive benchmarks challenging to create. Moreover, the current proposed ML solutions do not consider the necessity of adapting to IoT networks that mutate fast. We propose a Continuous Learning approach to anomaly detection on IoT networks: frequent model retraining and the exploitation of previous knowledge allow a classifier to quickly adapt to new network configurations. We deployed this approach firstly by defining a benchmark methodology for ML algorithms that helps train and test models for anomaly detection in IoT networks. This phase allowed us to identify the best-performing algorithm for the task. Then, we employed Semi-supervised Learning techniques to deploy the continuous part concretely. Our results show that applying Continuous Learning can progressively improve anomaly detection performance in key metrics such as Recall (up to 75%) and Roc AUC (up to 33%).
Giacomo Quadrio, Roberto Pompa, Enrico Bassetti, Ciro D'Elia, Gianluca Scacco, Mauro Conti
WiMob3
2023 A New Model for Testing IPv6 Fragment Handling
Edoardo Di Paolo, Enrico Bassetti, Angelo Spognardi
ESORICS (2)2
2022 ISIDE: Proactively Assist University Students at Risk of Dropout
abstract
In this work, we present ISIDE, the prototype of a student dropout alert system integrated within Infostud, i.e., the online student portal of the Sapienza University of Rome. Our proposed solution is based on a student dropout prediction (SDP) module built from a large dataset of academic records using advanced machine learning techniques. Offline experiments show that the best-performing SDP model can detect students prone to leave the school with an F1score of 0.92. To further validate our prototype online, we run a pilot study on a subset of students from our School of Information Engineering, Informatics, and Statistics. This study shows that our prototype can detect students who are most likely to drop out early, as it clearly separates them from those with higher key engagement indicators.
Enrico Bassetti, Andrea Conti 0003, Emanuele Panizzi, Gabriele Tolomei
IEEE Big Data1
2021 ML Classification of Car Parking with Implicit Interaction on the Driver's Smartphone
Enrico Bassetti, Alessio Luciani, Emanuele Panizzi
INTERACT (3)1