Simone Bussa

dblp:325/8855 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2026
0009-0001-2563-1074ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 FDO Protocol: A Possible Solution to Protect the Ownership Voucher Against Untrusted Supply Chain
abstract
The FDO protocol is the leading candidate to become the reference standard for automatic device onboarding. However, as documented in the literature, it may suffer from a security issue exploiting its Ownership Voucher when the supply chain of the device cannot be considered trusted. In a previous work, we showed a possible attack of this type, found by performing a formal analysis on a symbolic model of the protocol. The first contribution of this paper is to present the analysis done in the previous work in a more comprehensive way, to extend it, and to show that the attack found is also possible on a real implementation of the protocol. We then analyse some possible solutions proposed in the literature as countermeasures to try to mitigate the attack. After demonstrating that they may not completely solve the mentioned issue, we propose our own solution, which could be taken into consideration by the FIDO Working Group to further improve the protocol specification. Again, as a demonstration of the logical correctness of our solution, we formally analyse its symbolic model.
Simone Bussa, Riccardo Sisto, Fulvio Valenza
IEEE Trans. Dependable Secur. Comput.1
2025 Formal verification of a V2X scheme mixing traditional PKI and group signatures
abstract
Vehicle-to-Everything (V2X) communications are expected to reshape road mobility in the increasingly near future. This type of communication allows a vehicle to transmit information, such as its position and speed, which can be used for different applications. However, despite the benefits, the increased connectivity and data sent over the network may expose the vehicle to a significant number of cyber attacks. This paper takes one of the schemes proposed in the literature to protect the security and privacy of the vehicles, and analyses it from a security and privacy perspective using Proverif. Specifically, this scheme is unique in combining asymmetric encryption with digital certificates and group signatures used by vehicles to self-certify those certificates. We present a formal model able to capture all the main aspects of the protocol and the context in which it works, and show how security and privacy properties can be expressed for formal verification in Proverif. Our analysis conducted on the model of the protocol revealed some weaknesses for which we tried to provide a solution.
Simone Bussa, Riccardo Sisto, Fulvio Valenza
J. Inf. Secur. Appl.1
2025 Atomizing Firewall Policies for Anomaly Analysis and Resolution
abstract
Nowadays, the security management of packet filtering firewall policies got complicated due to the evolution of modern computer networks, characterized by growing size and heterogeneity of communications. The traditional manual approaches for configuring firewalls have become error-prone, unoptimized and time-consuming, leading to an increasing number of policy anomalies, including both sub-optimizations and conflicts. In literature, the techniques proposed for anomaly management have several shortcomings, as their anomaly analysis is usually excessively complex, while their anomaly resolution cannot solve all anomalies. In order to overcome these shortcomings, this article proposes a comprehensive approach for firewall policy anomaly analysis and resolution, based on the formal concept of atomic predicates. This approach has the aim to simplify the anomaly management operations, make them efficient and solve all configuration anomalies. The achievement of these objectives has been experimentally proved through the validation of a framework which implements the proposed approach, and whose time performance and anomaly management efficiency have been compared with the relevant alternative approaches.
Daniele Bringhenti, Simone Bussa, Riccardo Sisto, Fulvio Valenza
IEEE Trans. Dependable Secur. Comput.2
2024 PAKA: Pseudonymous Authenticated Key Agreement without bilinear cryptography
abstract
Anonymity and pseudonymity are important concepts in the domain of the Internet of Things. The existing privacy-preserving key agreement schemes are only concerned with maintaining the privacy of the communicated data that appears on the channel established between two honest entities. However, privacy should also include anonymity or pseudonymity of the device identity. This means there should not exist any correlation handle to associate different communications done by the device.
Raphael Schermann, Simone Bussa, Rainer Urian, Ronald Toegl, Christian Steger
ARES2
2024 A Two-Fold Traffic Flow Model for Network Security Management
abstract
Introducing formal methods in the automatic resolution of network security management problems can guarantee solution correctness, so also boosting human confidence in using automatic techniques. A necessary step to achieve this feature is the definition of formal network models, representing network topology, traffic flows, etc. Each state-of-the-art formal network modeling approach has been proposed and validated only for a specific management problem (e.g., verification of configurations or refinement of policies into configurations). This paper analyzes a possible combination of the most promising state-of-the-art modeling approaches into a unified formal model that can be used by existing automatic resolution algorithms to solve both the verification and the refinement problems, without the need of major changes. The model is flexible enough to allow different aggregation levels of traffic into flows. The paper analyzes two opposite flow aggregation strategies, named Atomic Flows and Maximal Flows, and compares their performance when applied to the two identified security problems.
Daniele Bringhenti, Simone Bussa, Riccardo Sisto, Fulvio Valenza
IEEE Trans. Netw. Serv. Manag.2
2022 Security Automation using Traffic Flow Modeling
abstract
he growing trend towards network “softwarization” allows the creation and deployment of even complex network environments in a few minutes or seconds, rather than days or weeks as required by traditional methods. This revolutionary approach made it necessary to seek automatic processes to solve network security problems. One of the main issues in the automation of network security concerns the proper and efficient modeling of network traffic. In this paper, we describe two optimized Traffic Flows representation models, called Atomic Flows and Maximal Flows. In addition to the description, we have validated and evaluated the proposed models to solve two key network security problems - security verification and automatic configuration - showing the advantages and limitations of each solution.
Simone Bussa, Riccardo Sisto, Fulvio Valenza
NetSoft1