EDBT 2026 Demo / reviewers in the wild / expert
Daniele Granata
dblp:293/6205
· DBLP profile ↗
12ranked-venue papers
6as first author
12since 2021 · last 2026
0000-0002-6776-9485ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Systematic Threat Search to pentesting: Industrial Control Systems threat modelsabstractThe rapid digitalization of industrial environments and the increasing convergence of Information Technology (IT) and Operational Technology (OT) have transformed traditional Industrial Control Systems (ICS) into complex Cyber-Physical Systems (CPS). While this evolution enables unprecedented levels of efficiency and automation, it exposes critical infrastructures to a sophisticated and heterogeneous threat landscape where attacks can propagate beyond digital assets to cause production disruptions. Despite the sector’s criticality, current literature suffers from methodological fragmentation; most studies rely on empirical enumeration or ad-hoc processes, lacking structured frameworks for threat identification. This paper addresses this gap by presenting a Systematic Literature Review (SLR) designed to establish a formalized knowledge base for ICS threat modeling. Through a rigorous search of 913 scientific publications, we identified the most relevant contributions to threat definition. The primary contribution of this work is the development of a comprehensive ICS Threat Catalogue, which systematically classifies 87 distinct threats. These threats are mapped to specific assets and communication protocols, aligned with the Purdue Enterprise Reference Architecture. By integrating these findings into a graph-based modeling approach, we leveraged an automated methodology for generating threat models and penetration testing plans. The effectiveness of the catalogue was validated through a Smart Manufacturing case study, where the approach successfully identified 481 potential threats and generated 319 attack plans, demonstrating the practical impact of threat analysis and operational security assessment. Daniele Granata, Antonio Iannaccone, Roberto Nardone, Luigi Romano |
Comput. Secur. | 1 |
| 2025 | A Cyclical Penetration Testing Automation Methodology: The JetRacer Case Study
Daniele Granata, Massimiliano Rak, Felice Moretta, Fabio Fiumara |
AINA (2) | 1 |
| 2025 | NLP-Driven Analysis of Users' Reaction for Estimation of Information Disorder Propagation
Gennaro Junior Pezzullo, Alba Amato, Beniamino Di Martino, Daniele Granata, Massimiliano Rak, Salvatore Venticinque |
AINA (8) | 4 |
| 2024 | Advancing ESSecA: a step forward in Automated Penetration TestingabstractThe growing importance of Information Technology (IT) services is accompanied by a surge in security challenges. While traditional security tests focus on single applications, today’s interconnected systems require a broader evaluation. Vulnerability Assessment and Penetration Testing (VAPT) is a method to tackle this, aiming to assess whole systems thoroughly. However, performing VAPT manually is time-consuming and costly. Therefore, there’s a strong need for automating these processes. In response to these challenges, a novel methodology, named ESSecA built upon existing literature to guide the penetration testers during the assessment of a system based on threat intelligence mechanisms. This paper presents enhancements to the ESSecA methodology, including a formal Penetration Test Plan (PTP) model, a taxonomy for Penetration Test phases, and an innovative pattern match system integrated with a Tool Catalogue knowledge base used to improve the Expert System. These developments culminated in an algorithm facilitating the automatic generation of Penetration Test Plans, thus advancing the automation of security assessment processes. Massimiliano Rak, Felice Moretta, Daniele Granata |
ARES | 3 |
| 2024 | Navigating IoT Complexity: Developing Datasets for Smart-Home Device Interactions
Massimiliano Rak, Daniele Granata, Antonio Esposito 0001, Antonio Ferretti |
CISIS | 2 |
| 2024 | Systematic Threat Modelling of High-Performance Computing Systems: The V: HPCCRI Case Study
Raffaele Elia, Daniele Granata, Massimiliano Rak |
CLOSER | 2 |
| 2024 | Systematic analysis of automated threat modelling techniques: Comparison of open-source toolsabstractAbstract Companies face increasing pressure to protect themselves and their customers from security threats. Security by design is a proactive approach that builds security into all aspects of a system from the ground up, rather than adding it on as an afterthought. By taking security into account at every stage of development, organizations can create systems that are more resistant to attacks and better able to recover from them if they do occur. One of the most relevant practices is threat modelling, i.e. the process of identifying and analysing the security threat to an information system, application, or network. These processes require security experts with high skills to anticipate possible issues: therefore, it is a costly task and requires a lot of time. To face these problems, many different automated threat modelling methodologies are emerging. This paper first carries out a systematic literature review (SLR) aimed at both having an overview of the automated threat modelling techniques used in literature and enumerating all the tools that implement these techniques. Then, an analysis was carried out considering four open-source tools and a comparison with our threat modelling approach using a simple, but significant case study: an e-commerce site developed on top of WordPress. Daniele Granata, Massimiliano Rak |
Softw. Qual. J. | 1 |
| 2023 | Semi-Automatic PenTest Methodology based on Threat-Model: The IoT Brick Case StudyabstractIntegration of the Internet of Things (IoT) with cloud computing has accelerated the emergence of a wide range of new applications in different areas, such as manufacturing, supply chains, commercial, engineering, etc. On the other hand, security represents a severe limitation in the adoption of IoT technology in many contexts. Although the cloud paradigm offers and enables flexible adoptions of on-demand services to a variety of IoT applications, due to limited resources of IoT devices and rapid implementation, IoT-cloud-based infrastructures are prone to numerous security vulnerabilities and threats. Therefore, it has become imperative to develop or enhance security strategies. Ideally, security should be built in from the early stages of a new product’s development, which often starts as a prototype for internal use and then becomes an end-user product. Therefore, it is necessary to certify the level of security through vulnerability assessments or penetration tests, before the product is made available to the general public. Since both activities are time-and resource-consuming, a semi-automatic penetration testing technique based on the PETIoT framework has been proposed. The suggested approach can be used to evaluate the security of a system that’s already in place. It takes into account potential threats, likely attacks, and provides recommendations for improvements. The methodology has been applied to a common IoT case study: the IoT Brick by Babuino Controllers. Gennaro Pio Rimoli, Daniele Granata, Massimo Ficco |
CloudCom | 2 |
| 2023 | Automated threat modelling and risk analysis in e-Government using BPMNabstractRecent progress integrates security requirements into BPMN, enhancing its framework. Extensions aim to seamlessly embed security concepts, yet the inherent ambiguity of security terms may lead to misinterpretations and vulnerabilities. Unfortunately, many business process experts lack the expertise to accurately interpret and integrate vital security concepts. In this study, we present an innovative automated methodology tailored to assist business process experts in identifying security threats and conducting risk assessments, particularly in the context of e-Government processes. Our approach streamlines the process, requiring only a business specialist to annotate BPMN entities with high-level, non-security-related information. Based on these annotations, potential threats to the system can be automatically identified. To develop our methodology, we leverage the standard BPMN annotation mechanism. From the annotated BPMN, the methodology utilises the ENISA Threat Landscape knowledge base for threat identification and employs the OWASP Risk Rating Methodology for risk assessment. To demonstrate the effectiveness of our approach, we applied it to a straightforward case study within the e-Government domain. Through this example, we illustrate how our methodology can be employed to ensure compliance with the General Data Protection Regulation and meet the mandatory Data Protection Impact Assessment requirements. Daniele Granata, Massimiliano Rak, Giovanni Salzillo, Giacomo Di Guida, Salvatore Petrillo |
Connect. Sci. | 1 |
| 2022 | MetaSEnD: A Security Enabled Development Life Cycle Meta-ModelabstractThe growing adoption of IT infrastructures determined a high heterogeneity of software systems. As matter of fact, the software is prone to vulnerabilities and cybersecurity problems, which are challenging to manage during the software lifecycle. The situation is further compounded by the growing demand for rapid application development and the widespread diffusion of Agile methodologies and the DevOps culture. This process promotes collaboration within and between the different groups involved in software development. In recent years there has been a spread of new or adapted security-oriented methodologies providing different approaches to identify security problems in the early stages of the software development life cycle (SDLC), thus reducing the costs for the security assessment. SecDevOps is just an example of the integration and promotion of security aspects in DevOps organizations. While these methodologies help to produce more reliable software, on other hand they are difficult to integrate into standard or customized SDLC, or with design evaluation and risk management methodologies. This work analyzes the state of the art and aims at identifying the main activities in a Secure Software Development Life Cycle (SSDLC), by proposing a new secure software development lifecycle meta-model (MetaSEnD). MetaSEnD has also been applied in a continuous integration pipeline of a sample microservices application. Daniele Granata, Massimiliano Rak, Giovanni Salzillo |
ARES | 1 |
| 2022 | A Semantic Methodology for Security Controls Verification in Public Administration Business Processes
Massimiliano Rak, Daniele Granata, Beniamino Di Martino, Luigi Colucci Cante |
CISIS | 2 |
| 2021 | Design and Development of a Technique for the Automation of the Risk Analysis Process in IT Security
Daniele Granata, Massimiliano Rak |
CLOSER | 1 |