Marco Cova

dblp:36/2855 · DBLP profile ↗
← Back
24ranked-venue papers
4as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1Computer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
13 papers
Malware analysis · 35% Network security · 20% Web and mobile security · 16%
Software engineering, system software, and programming languages
4 papers
Software testing · 64% Program analysis · 36%
Databases, data mining, and information retrieval
2 papers
Information retrieval · 61% Data integration and cleaning · 39%
Artificial intelligence
1 paper
Knowledge representation and reasoning · 87% Multi-agent systems · 13%

Topics — the 29 heaviest of 35, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › intrusion detection and prevention
intrusion detection
0.612022
DEEPCASE: Semi-Supervised Contextual Analysis of Security Events · SP 2022
Malware analysis › web-based malware
drive-by download detection
0.432012
EvilSeed: A Guided Approach to Finding Malicious Web Pages · IEEE Symposium on Security and Privacy 2012
Prophiler: a fast filter for the large-scale detection of malicious web pages · WWW 2011
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Malware analysis
web-based malware
0.322013
Revolver: An Automated Approach to the Detection of Evasive Web-based Malware · USENIX Security Symposium 2013
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Web and mobile security › web security
malicious website detection
0.322012
EvilSeed: A Guided Approach to Finding Malicious Web Pages · IEEE Symposium on Security and Privacy 2012
Prophiler: a fast filter for the large-scale detection of malicious web pages · WWW 2011
Cryptographic protocols and secure computation › electronic voting
electronic voting security
0.222010
An Experience in Testing the Security of Real-World Electronic Voting Systems · IEEE Trans. Software Eng. 2010
Are your votes really counted?: testing the security of real-world electronic voting systems · ISSTA 2008
Usable security
security operations
0.212022
DEEPCASE: Semi-Supervised Contextual Analysis of Security Events · SP 2022
Malware analysis › adversarial malware detection
evasive malware detection
0.212013
Revolver: An Automated Approach to the Detection of Evasive Web-based Malware · USENIX Security Symposium 2013
Software testing › non-functional testing
security testing
0.122010
Are your votes really counted?: testing the security of real-world electronic voting systems · ISSTA 2008
An Experience in Testing the Security of Real-World Electronic Voting Systems · IEEE Trans. Software Eng. 2010
Malware analysis › web-based malware
drive-by downloads
0.112010
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Malware analysis › web-based malware
malicious javascript detection
0.112010
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Malware analysis
malware detection
0.112010
Efficient Detection of Split Personalities in Malware · NDSS 2010
Systems and software security
vulnerability analysis
0.112010
An Experience in Testing the Security of Real-World Electronic Voting Systems · IEEE Trans. Software Eng. 2010
Web and mobile security
web security
0.112010
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Systems and software security
vulnerability discovery
0.122008
Multi-module vulnerability analysis of web-based applications · CCS 2007
Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications · SP 2008
Malware analysis › botnet
botnet analysis
0.112009
Your botnet is my botnet: analysis of a botnet takeover · CCS 2009
Systems and software security
security testing
0.112008
Are your votes really counted?: testing the security of real-world electronic voting systems · ISSTA 2008
Hardware security and side channels
side channel
0.112008
ClearShot: Eavesdropping on Keyboard Input from Video · SP 2008
Security and privacy of machine learning › privacy attack
side-channel eavesdropping
0.112008
ClearShot: Eavesdropping on Keyboard Input from Video · SP 2008
Web and mobile security
web application vulnerability
0.112008
Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications · SP 2008
Web and mobile security
web application security
0.112007
Multi-module vulnerability analysis of web-based applications · CCS 2007
Knowledge, reasoning and agents › Knowledge representation and reasoning
ontology
0.112005
Shared lexicon for distributed annotations on the Web · WWW 2005
Knowledge, reasoning and agents › Knowledge representation and reasoning › ontology
ontology matching
0.112005
Shared lexicon for distributed annotations on the Web · WWW 2005
Data integration and cleaning › interoperability
semantic interoperability
0.112005
Shared lexicon for distributed annotations on the Web · WWW 2005
Information retrieval › search engines
crawling
0.012012
EvilSeed: A Guided Approach to Finding Malicious Web Pages · IEEE Symposium on Security and Privacy 2012
Information retrieval
search engines
0.012012
EvilSeed: A Guided Approach to Finding Malicious Web Pages · IEEE Symposium on Security and Privacy 2012
Program analysis
dynamic analysis
0.012010
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Program analysis › dynamic language analysis
javascript analysis
0.012010
Detection and analysis of drive-by-download attacks and malicious JavaScript code · WWW 2010
Systems and software security
election security
0.012008
Are your votes really counted?: testing the security of real-world electronic voting systems · ISSTA 2008
Systems and software security › software vulnerability
injection vulnerabilities
0.012008
Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications · SP 2008

Methods — techniques the papers use, named apart from their topics

semi-supervised learning · 0.6dynamic analysis · 0.5machine learning · 0.3seed-based query generation · 0.3static analysis · 0.2javascript analysis · 0.2prefiltering · 0.1pre-filtering · 0.1static filtering · 0.1network trace analysis · 0.1infrastructure hijacking · 0.1social engineering · 0.1penetration testing · 0.1lexical approaches · 0.1security testing · 0.1language games · 0.1language game · 0.1
YearPublicationVenuePosition
2022 DEEPCASE: Semi-Supervised Contextual Analysis of Security Events
abstract
Security monitoring systems detect potentially malicious activities in IT infrastructures, by either looking for known signatures or for anomalous behaviors. Security operators investigate these events to determine whether they pose a threat to their organization. In many cases, a single event may be insufficient to determine whether certain activity is indeed malicious. Therefore, a security operator frequently needs to correlate multiple events to identify if they pose a real threat. Unfortunately, the vast number of events that need to be correlated often overload security operators, forcing them to ignore some events and, thereby, potentially miss attacks. This work studies how to automatically correlate security events and, thus, automate parts of the security operator workload. We design and evaluate DEEPCASE, a system that leverages the context around events to determine which events require further inspection. This approach reduces the number of events that need to be inspected. In addition, the context provides valuable insights into why certain events are classified as malicious. We show that our approach automatically filters 86.72% of the events and reduces the manual workload of security operators by 90.53%, while underestimating the risk of potential threats in less than 0.001% of cases.
Thijs van Ede, Hojjat Aghakhani, Noah Spahn, Riccardo Bortolameotti, Marco Cova, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Christopher Krügel, Giovanni Vigna
SP5
2013 Revolver: An Automated Approach to the Detection of Evasive Web-based Malware
Alexandros Kapravelos, Yan Shoshitaishvili, Marco Cova, Christopher Krügel, Giovanni Vigna
USENIX Security Symposium3
2012 The Unbearable Lightness of Monitoring: Direct Monitoring in BitTorrent
Tom Chothia, Marco Cova, Chris Novakovic, Camilo González Toro
SecureComm2
2012 EvilSeed: A Guided Approach to Finding Malicious Web Pages
abstract
Malicious web pages that use drive-by download attacks or social engineering techniques to install unwanted software on a user's computer have become the main avenue for the propagation of malicious code. To search for malicious web pages, the first step is typically to use a crawler to collect URLs that are live on the Internet. Then, fast prefiltering techniques are employed to reduce the amount of pages that need to be examined by more precise, but slower, analysis tools (such as honey clients). While effective, these techniques require a substantial amount of resources. A key reason is that the crawler encounters many pages on the web that are benign, that is, the "toxicity" of the stream of URLs being analyzed is low. In this paper, we present EVILSEED, an approach to search the web more efficiently for pages that are likely malicious. EVILSEED starts from an initial seed of known, malicious web pages. Using this seed, our system automatically generates search engines queries to identify other malicious pages that are similar or related to the ones in the initial seed. By doing so, EVILSEED leverages the crawling infrastructure of search engines to retrieve URLs that are much more likely to be malicious than a random page on the web. In other words EVILSEED increases the "toxicity" of the input URL stream. Also, we envision that the features that EVILSEED presents could be directly applied by search engines in their prefilters. We have implemented our approach, and we evaluated it on a large-scale dataset. The results show that EVILSEED is able to identify malicious web pages more efficiently when compared to crawler-based approaches.
Luca Invernizzi, Paolo Milani Comparetti, Stefano Benvenuti, Christopher Krügel, Marco Cova, Giovanni Vigna
IEEE Symposium on Security and Privacy5
2011 Escape from Monkey Island: Evading High-Interaction Honeyclients
Alexandros Kapravelos, Marco Cova, Christopher Krügel, Giovanni Vigna
DIMVA2
2011 Peering through the iframe
abstract
Drive-by-download attacks have become the method of choice for cyber-criminals to infect machines with malware. Previous research has focused on developing techniques to detect web sites involved in drive-by-download attacks, and on measuring their prevalence by crawling large portions of the Internet. In this paper, we take a different approach at analyzing and understanding drive-by-download attacks. Instead of horizontally searching the Internet for malicious pages, we examine in depth one drive-by-download campaign, that is, the coordinated efforts used to spread malware. In particular, we focus on the Mebroot campaign, which we periodically monitored and infiltrated over several months, by hijacking parts of its infrastructure and obtaining network traces at an exploit server. By studying the Mebroot drive-by-download campaign from the inside, we could obtain an in-depth and comprehensive view into the entire life-cycle of this campaign and the involved parties. More precisely, we could study the security posture of the victims of drive-by attacks (e.g., by measuring the prevalence of vulnerable software components and the effectiveness of software updating mechanisms), the characteristics of legitimate web sites infected during the campaign (e.g., the infection duration), and the modus operandi of the miscreants controlling the campaign.
Brett Stone-Gross, Marco Cova, Christopher Krügel, Giovanni Vigna
INFOCOM2
2011 Prophiler: a fast filter for the large-scale detection of malicious web pages
abstract
Malicious web pages that host drive-by-download exploits have become a popular means for compromising hosts on the Internet and, subsequently, for creating large-scale botnets. In a drive-by-download exploit, an attacker embeds a malicious script (typically written in JavaScript) into a web page. When a victim visits this page, the script is executed and attempts to compromise the browser or one of its plugins. To detect drive-by-download exploits, researchers have developed a number of systems that analyze web pages for the presence of malicious code. Most of these systems use dynamic analysis. That is, they run the scripts associated with a web page either directly in a real browser (running in a virtualized environment) or in an emulated browser, and they monitor the scripts' executions for malicious activity. While the tools are quite precise, the analysis process is costly, often requiring in the order of tens of seconds for a single page. Therefore, performing this analysis on a large set of web pages containing hundreds of millions of samples can be prohibitive.
Davide Canali, Marco Cova, Giovanni Vigna, Christopher Krügel
WWW2
2010 Organizing Large Scale Hacking Competitions
Nicholas Childers, Bryce Boe, Lorenzo Cavallaro, Ludovico Cavedon, Marco Cova, Manuel Egele, Giovanni Vigna
DIMVA5
2010 Why Johnny Can't Pentest: An Analysis of Black-Box Web Vulnerability Scanners
Adam Doupé, Marco Cova, Giovanni Vigna
DIMVA2
2010 Efficient Detection of Split Personalities in Malware
Davide Balzarotti, Marco Cova, Christoph Karlberger, Engin Kirda, Christopher Krügel, Giovanni Vigna
NDSS2
2010 An Analysis of Rogue AV Campaigns
Marco Cova, Corrado Leita, Olivier Thonnard, Angelos D. Keromytis, Marc Dacier
RAID1
2010 Detection and analysis of drive-by-download attacks and malicious JavaScript code
abstract
JavaScript is a browser scripting language that allows developers to create sophisticated client-side interfaces for web applications. However, JavaScript code is also used to carry out attacks against the user's browser and its extensions. These attacks usually result in the download of additional malware that takes complete control of the victim's platform, and are, therefore, called "drive-by downloads." Unfortunately, the dynamic nature of the JavaScript language and its tight integration with the browser make it difficult to detect and block malicious JavaScript code.
Marco Cova, Christopher Krügel, Giovanni Vigna
WWW1
2010 An Experience in Testing the Security of Real-World Electronic Voting Systems
abstract
Voting is the process through which a democratic society determines its government. Therefore, voting systems are as important as other well-known critical systems, such as air traffic control systems or nuclear plant monitors. Unfortunately, voting systems have a history of failures that seems to indicate that their quality is not up to the task. Because of the alarming frequency and impact of the malfunctions of voting systems, in recent years a number of vulnerability analysis exercises have been carried out against voting systems to determine if they can be compromised in order to control the results of an election. We have participated in two such large-scale projects, sponsored by the Secretaries of State of California and Ohio, whose goals were to perform the security testing of the electronic voting systems used in their respective states. As the result of the testing process, we identified major vulnerabilities in all of the systems analyzed. We then took advantage of a combination of these vulnerabilities to generate a series of attacks that would spread across the voting systems and would “steal” votes by combining voting record tampering with social engineering approaches. As a response to the two large-scale security evaluations, the Secretaries of State of California and Ohio recommended changes to improve the security of the voting process. In this paper, we describe the methodology that we used in testing the two real-world electronic voting systems we evaluated, the findings of our analysis, our attacks, and the lessons we learned.
Davide Balzarotti, Greg Banks, Marco Cova, Viktoria Felmetsger, Richard A. Kemmerer, William K. Robertson, Fredrik Valeur, Giovanni Vigna
IEEE Trans. Software Eng.3
2009 Analyzing and Detecting Malicious Flash Advertisements
abstract
The amount of dynamic content on the Web has been steadily increasing. Scripting languages such as JavaScript and browser extensions such as Adobe's Flash have been instrumental in creating Web-based interfaces that are similar to those of traditional applications. Dynamic content has also become popular in advertising, where Flash is used to create rich, interactive ads that are displayed on hundreds of millions of computers per day. Unfortunately, the success of Flash-based advertisements and applications attracted the attention of malware authors, who started to leverage Flash to deliver attacks through advertising networks. This paper presents a novel approach whose goal is to automate the analysis of Flash content to identify malicious behavior. We designed and implemented a tool based on the approach, and we tested it on a large corpus of real-world Flash advertisements. The results show that our tool is able to reliably detect malicious Flash ads with limited false positives. We made our tool available publicly and it is routinely used by thousands of users.
Sean Ford, Marco Cova, Christopher Krügel, Giovanni Vigna
ACSAC2
2009 Your botnet is my botnet: analysis of a botnet takeover
abstract
Botnets, networks of malware-infected machines that are controlled by an adversary, are the root cause of a large number of security problems on the Internet. A particularly sophisticated and insidious type of bot is Torpig, a malware program that is designed to harvest sensitive information (such as bank account and credit card data) from its victims. In this paper, we report on our efforts to take control of the Torpig botnet and study its operations for a period of ten days. During this time, we observed more than 180 thousand infections and recorded almost 70 GB of data that the bots collected. While botnets have been "hijacked" and studied previously, the Torpig botnet exhibits certain properties that make the analysis of the data particularly interesting. First, it is possible (with reasonable accuracy) to identify unique bot infections and relate that number to the more than 1.2 million IP addresses that contacted our command and control server. Second, the Torpig botnet is large, targets a variety of applications, and gathers a rich and diverse set of data from the infected victims. This data provides a new understanding of the type and amount of personal information that is stolen by botnets.
Brett Stone-Gross, Marco Cova, Lorenzo Cavallaro, Bob Gilbert, Martin Szydlowski, Richard A. Kemmerer, Christopher Krügel, Giovanni Vigna
CCS2
2008 Are your votes really counted?: testing the security of real-world electronic voting systems
abstract
Electronic voting systems play a critical role in today's democratic societies, as they are responsible for recording and counting the citizens' votes. Unfortunately, there is an alarming number of reports describing the malfunctioning of these systems, suggesting that their quality is not up to the task. Recently, there has been a focus on the security testing of voting systems to determine if they can be compromised in order to control the results of an election. We have participated in two large-scale projects, sponsored by the Secretaries of State of California and Ohio, whose respective goals were to perform the security testing of the electronic voting systems used in those two states. The testing process identified major flaws in all the systems analyzed, and resulted in substantial changes in the voting procedures of both states. In this paper, we describe the testing methodology that we used in testing two real-world electronic voting systems, the findings of our analysis, and the lessons we learned.
Davide Balzarotti, Greg Banks, Marco Cova, Viktoria Felmetsger, Richard A. Kemmerer, William K. Robertson, Fredrik Valeur, Giovanni Vigna
ISSTA3
2008 Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications
abstract
Web applications are ubiquitous, perform mission- critical tasks, and handle sensitive user data. Unfortunately, web applications are often implemented by developers with limited security skills, and, as a result, they contain vulnerabilities. Most of these vulnerabilities stem from the lack of input validation. That is, web applications use malicious input as part of a sensitive operation, without having properly checked or sanitized the input values prior to their use. Past research on vulnerability analysis has mostly focused on identifying cases in which a web application directly uses external input in critical operations. However, little research has been performed to analyze the correctness of the sanitization process. Thus, whenever a web application applies some sanitization routine to potentially malicious input, the vulnerability analysis assumes that the result is innocuous. Unfortunately, this might not be the case, as the sanitization process itself could be incorrect or incomplete. In this paper, we present a novel approach to the analysis of the sanitization process. More precisely, we combine static and dynamic analysis techniques to identify faulty sanitization procedures that can be bypassed by an attacker. We implemented our approach in a tool, called Saner, and we applied it to a number of real-world applications. Our results demonstrate that we were able to identify several novel vulnerabilities that stem from erroneous sanitization procedures.
Davide Balzarotti, Marco Cova, Viktoria Felmetsger, Nenad Jovanovic, Engin Kirda, Christopher Krügel, Giovanni Vigna
SP2
2008 ClearShot: Eavesdropping on Keyboard Input from Video
abstract
Eavesdropping on electronic communication is usually prevented by using cryptography-based mechanisms. However, these mechanisms do not prevent one from obtaining private information through side channels, such as the electromagnetic emissions of monitors or the sound produced by keyboards. While extracting the same information by watching somebody typing on a keyboard might seem to be an easy task, it becomes extremely challenging if it has to be automated. However, an automated tool is needed in the case of long-lasting surveillance procedures or long user activity, as a human being is able to reconstruct only a few characters per minute. This paper presents a novel approach to automatically recovering the text being typed on a keyboard, based solely on a video of the user typing. As part of the approach, we developed a number of novel techniques for motion tracking, sentence reconstruction, and error correction. The approach has been implemented in a tool, called ClearShot, which has been tested in a number of realistic settings where it was able to reconstruct a substantial part of the typed information.
Davide Balzarotti, Marco Cova, Giovanni Vigna
SP2
2007 Multi-module vulnerability analysis of web-based applications
abstract
In recent years, web applications have become tremendously popular, and nowadays they are routinely used in security-critical environments, such as medical, financial, and military systems. As the use of web applications for critical services has increased, the number and sophistication of attacks against these applications have grown as well. Current approaches to securing web applications focus either on detecting and blocking web-based attacks using application-level firewalls, or on using vulnerability analysis techniques to identify security problems before deployment.
Davide Balzarotti, Marco Cova, Viktoria Felmetsger, Giovanni Vigna
CCS2
2007 Swaddler: An Approach for the Anomaly-Based Detection of State Violations in Web Applications
Marco Cova, Davide Balzarotti, Viktoria Felmetsger, Giovanni Vigna
RAID1
2006 Static Detection of Vulnerabilities in x86 Executables
abstract
Several approaches have been proposed to perform vulnerability analysis of applications written in high-level languages. However, little has been done to automatically identify security-relevant flaws in binary code. In this paper, we present a novel approach to the identification of vulnerabilities in x86 executables in ELF binary format. Our approach is based on static analysis and symbolic execution techniques. We implemented our approach in a proof-of-concept tool and used it to detect taint-style vulnerabilities in binary code. The results of our evaluation show that our approach is both practical and effective
Marco Cova, Viktoria Felmetsger, Greg Banks, Giovanni Vigna
ACSAC1
2006 SNOOZE: Toward a Stateful NetwOrk prOtocol fuzZEr
Greg Banks, Marco Cova, Viktoria Felmetsger, Kevin C. Almeroth, Richard A. Kemmerer, Giovanni Vigna
ISC2
2005 Language Games: Solving the Vocabulary Problem in Multi-Case-Base Reasoning
Paolo Avesani, Conor Hayes, Marco Cova
ICCBR3
2005 Shared lexicon for distributed annotations on the Web
abstract
The interoperability among distributed and autonomous systems is the ultimate challenge facing the semantic web. Heterogeneity of data representation is the main source of problems. This paper proposes an innovative solution that combines lexical approaches and language games. The benefits for distributed annotation systems on the web are twofold: firstly, it will reduce the complexity of the semantic problem by moving the focus from the full-featured ontology level to the simpler lexicon level; secondly, it will avoid the drawback of a centralized third party mediator that may become a single point of failure.The main contributions of this work are concerned with:
Paolo Avesani, Marco Cova
WWW2