EDBT 2026 Demo / reviewers in the wild / expert
Massimo Ficco
dblp:49/1311
· DBLP profile ↗
45ranked-venue papers
16as first author
15since 2021 · last 2026
0000-0003-4199-8199ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 18 · 8 first-author · 3 since 2021Security and privacy · 5 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On-device training and pruning for energy saving and continuous learning in resource-constrained MCUs
Pietro Fusco, Gennaro Pio Rimoli, Antonio Guerriero, Francesco Palmieri 0002, Massimo Ficco |
Future Gener. Comput. Syst. | 5 |
| 2025 | TinyML-Based Intrusion Detection System for Handling Class Imbalance in IoT-Edge Domain Using Siamese Neural Network on MCU
Pietro Fusco, Alberto Montefusco, Gennaro Pio Rimoli, Francesco Palmieri 0002, Massimo Ficco |
AINA (3) | 5 |
| 2025 | Cross-Model Federated Learning-Based Network Traffic Classification
Kainat Ibrar, Francesco Palmieri 0002, Pietro Fusco, Massimo Ficco |
AINA (3) | 4 |
| 2025 | CTAT: A Blockchain-Driven Conditional Traceable Access Token for Enhancing Performance and Security in the Supply Chain of Sensitive Pharmaceuticals
Hadis Rezaei, Massimo Ficco, Francesco Palmieri 0002 |
AINA (8) | 2 |
| 2025 | Power Analysis of Post-quantum Cryptography NIST Algorithms in Resource-Constrained Microcontroller
Gennaro Pio Rimoli, Pietro Fusco, Massimo Ficco |
AINA (8) | 4 |
| 2025 | Context-aware coverage path planning for a swarm of UAVs using mobile ground stations for battery-swappingabstractAbstract The usage of swarms of drones is expected to continue growing in the next years, particularly in dangerous scenarios, such as monitoring and rescue missions in hostile and disaster areas. Small-sized Unmanned Aerial Vehicles (UAVs) are highly suitable for use in such scenarios due to their agility and maneuverability. On the other hand, their limited battery capacity poses significant challenges, especially during missions requiring full coverage of large areas in a short time and extreme weather conditions. This work proposed an energy efficiency approach, which makes use of mobile ground-based battery-swapping stations (BSSes), to speed up the UAV’s battery replacement and reduce energy waste in the round trip to the charging station. Specifically, a Context-Aware Coverage Path Planning (CACPP) problem has been formulated to determine the complete coverage path of a large area by a swarm of UAVs, minimizing the path overlapping and UAV battery swapping. The model takes into account the need to continue re-planning the mission, depending on the weather conditions (i.e., temperature and wind), the presence of obstacles, and the residual energy levels of the drones, as well as the relative positions of the drones and mobile BSSes. To solve the CACPP problem, an iterative approach leveraging two synchronized optimization models for planning UAV paths and BSS routes has been presented. As the CACPP problem is NP-hard, a heuristic procedure for solving it has also been evaluated. Experimental results show that it can be appropriate for large instances of the problem. Lorenzo Porcelli, Massimo Ficco, Gianni D'Angelo, Francesco Palmieri 0002 |
Soft Comput. | 2 |
| 2024 | XSS-Unearth: A Tool for Forensics Analysis of XSS Attacks
Davide Alfieri, Massimo Ficco, Michele Mastroianni, Francesco Palmieri 0002 |
AINA (5) | 2 |
| 2024 | When explainability turns into a threat - using xAI to fool a fake news detection methodabstractThe inclusion of Explainability of Artificial Intelligence (xAI) has become a mandatory requirement for designing and implementing reliable, interpretable and ethical AI solutions in numerous domains. xAI is now the subject of extensive research, from both the technical and social science perspectives. It is being received enthusiastically by legislative bodies and regular users of machine-learning-boosted applications alike. However, opening the black box of AI comes at a cost. This paper presents the results of the first study proving that xAI can enable successful adversarial attacks in the domain of fake news detection and lead to a decrease in AI security. We postulate the novel concept that xAI and security should strike a balance, especially in critical applications, such as fake news detection. An attack scheme against fake news detection methods is presented that employs an explainable solution. The described experiment demonstrates that the well-established SHAP explainer can be used to reshape the structure of the original message in such a way that the value of the model's prediction could be arbitrarily forced, whilst the meaning of the message stays the same. The paper presents various examples for which the SHAP values are used to point the adversary to the words and phrases that have to be changed to flip the label on the model prediction. To the best of the authors' knowledge, it has been the first research work to experimentally demonstrate the sinister side of xAI. As the generation and spreading of fake news has become a tool of modern warfare and a grave threat to democracy, the potential impact of explainable AI should be addressed as soon as possible. Rafal Kozik, Massimo Ficco, Aleksandra Pawlicka, Marek Pawlicki, Francesco Palmieri 0002, Michal Choras |
Comput. Secur. | 2 |
| 2024 | Testing the Resilience of MEC-Based IoT Applications Against Resource Exhaustion AttacksabstractMulti-access Edge Computing (MEC) is an emerging computing model that provides the necessary on-demand resources and services to the edge of the network, ensuring powerful computing, storage capacity, mobility, location, and context awareness support to emerging Internet of Things (IoT) applications. Nonetheless, its complex hierarchical model introduces new architectural interdependencies, which can influence the resilience of IoT applications against cyber attacks. Although application resilience has been investigated in the context of cloud computing, existing studies are not directly applicable to such an extended edge-cloud paradigm. The use of different enabling technologies at the edge of the network, such as various wireless access technologies and virtualization, implies several threats and challenges that make the analysis and deployment of resilience mechanisms a technically challenging problem. In this article, we first present an overview of the threat model, describing the threats for the different layers of this paradigm. We then study the impact of resource-exhausting attacks – a particularly relevant class for this paradigm - on three different IoT applications exploiting the services offered by the MEC-based architecture. We adopt a testing-based methodology conceived to characterize the resilience of such applications under attack. A set of most important resilience-related indicators are also identified. The characterization's results are useful to support the analyst in planning proper protection means at individual architectural layers. Roberto Pietrantuono, Massimo Ficco, Francesco Palmieri 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Semi-Automatic PenTest Methodology based on Threat-Model: The IoT Brick Case StudyabstractIntegration of the Internet of Things (IoT) with cloud computing has accelerated the emergence of a wide range of new applications in different areas, such as manufacturing, supply chains, commercial, engineering, etc. On the other hand, security represents a severe limitation in the adoption of IoT technology in many contexts. Although the cloud paradigm offers and enables flexible adoptions of on-demand services to a variety of IoT applications, due to limited resources of IoT devices and rapid implementation, IoT-cloud-based infrastructures are prone to numerous security vulnerabilities and threats. Therefore, it has become imperative to develop or enhance security strategies. Ideally, security should be built in from the early stages of a new product’s development, which often starts as a prototype for internal use and then becomes an end-user product. Therefore, it is necessary to certify the level of security through vulnerability assessments or penetration tests, before the product is made available to the general public. Since both activities are time-and resource-consuming, a semi-automatic penetration testing technique based on the PETIoT framework has been proposed. The suggested approach can be used to evaluate the security of a system that’s already in place. It takes into account potential threats, likely attacks, and provides recommendations for improvements. The methodology has been applied to a common IoT case study: the IoT Brick by Babuino Controllers. Gennaro Pio Rimoli, Daniele Granata, Massimo Ficco |
CloudCom | 3 |
| 2023 | Privacy-preserving malware detection in Android-based IoT devices through federated Markov chainsabstractThe continuous emergence of new and sophisticated malware specifically targeting Android-based Internet of Things devices is causing significant security hazards and is consequently fostering the need for effective detection models and strategies able to work with these hardware-constrained devices. In addition, since such models are often trained on confidential application data, many involved subjects are reluctant to share their data for this purpose. Accordingly, several Federated Learning-based solutions are emerging, which rely on the capabilities of Machine Learning models in malware detection/classification without sharing user data. However, Federated Learning methods are often adversely affected by non-independent and identically distributed data in terms of both the required training time and classification results. Therefore, a promising solution could be to overcome the Federated Learning-related issues by preserving the privacy of end-user data. In this direction, the capabilities of Markov chains and associative rules are extended within a federated environment to face malware classification tasks in the IoT scenario. The presented approach, evaluated on several malware families, has achieved an average accuracy of 99% in the presence of centralized and decentralized unbalanced training/testing data by overcoming the most common state-of-the-art approaches. Also, its runtime performance is comparable with centralized ones by considering several non-independent and identically distributed dataset partitions, splitting criteria, and clients, respectively. Gianni D'Angelo, Eslam Farsimadan, Massimo Ficco, Francesco Palmieri 0002, Antonio Robustelli |
Future Gener. Comput. Syst. | 3 |
| 2023 | Survivability Analysis of IoT Systems Under Resource Exhausting AttacksabstractEssential services in an Internet of Things (IoT)-based critical system should be continuously provided even when undesirable events like failures, attacks, and emergencies happen. In this work, we analyze the system’s ability to survive failures that are caused by resource exhaustion attacks. Such ability to survive means that the system’s services should be provided in compliance with the associated requirements also in presence of failures and other undesired events. Accordingly, we present a hybrid method (i.e., measurements- and model-based) to assess the expected survivability of an IoT system under resource-exhaustion attacks and, based on it, to optimize the preventive maintenance trigger period that maximizes survivability and minimizes the expected downtime cost. A realistic case study is implemented to emulate an IoT scenario and used to estimate the extent of resource consumption at each layer of the IoT stack when the system is subject to a resource-exhaustion attack. A semi-Markov process is then adopted to model the transient behavior of the system during an intrusion. The model is enriched with an additional state that represents a proactive recovery, in which the system is not available for a maintenance action aimed at preventing failure. The model solution gives the optimal maintenance triggering time. Roberto Pietrantuono, Massimo Ficco, Francesco Palmieri 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Malware Analysis by Combining Multiple Detectors and Observation WindowsabstractMalware developers continually attempt to modify the execution pattern of malicious code hiding it inside apparent normal applications, which makes its detection and classification challenging. This paper proposes an ensemble detector, which exploits the capabilities of the main analysis algorithms proposed in the literature designed to offer greater resilience to specific evasion techniques. In particular, the paper presents different methods to optimally combine both generic and specialized detectors during the analysis process, which can be used to increase the unpredictability of the detection strategy, as well as improve the detection rate in presence of unknown malware families and provide better detection performance in the absence of a constant re-training of detector needed to cope with the evolution of malware. The paper also presents an alpha-count mechanism that explores how the length of the observation time window can affect the detection accuracy and speed of different combinations of detectors during the malware analysis. An extended experimental campaign has been conducted on both an open-source sandbox and an Android smartphone with different malware datasets. A trade-off among performance, training time, and mean-time-to-detect is presented. Finally, a comparison with other ensemble detectors is also presented. Massimo Ficco |
IEEE Trans. Computers | 1 |
| 2021 | Intelligent Cloud Agents in Multi-participant Conversations for Cyber-Physical Exploitation of Cultural Heritage
Angelo Ambrisi, Rocco Aversa, Massimo Ficco, Danilo Cacace, Salvatore Venticinque |
AINA (3) | 3 |
| 2021 | Blockchain-based authentication and authorization for smart city applications
Christian Esposito 0001, Massimo Ficco, Brij B. Gupta |
Inf. Process. Manag. | 2 |
| 2020 | Malware detection in mobile environments based on Autoencoders and API-images
Gianni D'Angelo, Massimo Ficco, Francesco Palmieri 0002 |
J. Parallel Distributed Comput. | 2 |
| 2020 | Distributed Group Key Management for Event Notification Confidentiality Among SensorsabstractThere is an increasing involvement of the Internet of Things (IoT) in many of our daily activities, with the aim of improving their efficiency and effectiveness. We are witnessing the advent of smart cities, in which IoT is exploited to improve the management of a city's assets, as well as smart factories, where IoT is paving the way for the forth industrial revolution. These applications and many other ones imply several non-functional requirements to be satisfied by the adopted IoT solution, where security assumes paramount importance. Secure communications among the IoT nodes are strongly needed due to the use of wireless technologies that are easy to eavesdrop, in order to steal valuable information. Accordingly, confidentiality is a fundamental prerequisite, but the existing solutions based on transport-level encryption are ineffective, while the ones with application-level encryption may be too expensive in terms of energy consumption. In this work, we propose a series of solutions and methods to achieve confidentiality with end-to-end guarantees, by using group-based keys within the context of a clustered and distributed key management framework. We have implemented such solutions on top of TinyOS, and assessed their achievable quality by means of the TOSSIM simulator. Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Alfredo De Santis |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Detecting IoT Malware by Markov Chain Behavioral ModelsabstractInternet of Things (IoT) is become one of the most important technological sector in recent years, and the focus of attention in many fields, including military applications, healthcare, agriculture, industry, and space science, made it very attractive for cyber-attacks. Especially for the wide diffusion of the Adroid platform, the IoT devices are become one of the main targets of malware threats. Considering the great Android market share, it is needed to build effective tools able of detecting zero-day malware. Therefore, several static and dynamic analysis methods have been proposed in the literature. In this work, the sequences of API calls invoked by apps during their execution are modeled by Markov chains, and used to extract features of the apps through the time, needed for malware classification. The considered dataset includes 22K benign applications and 24K malware collected over different shared datasets. Experimental results show that the Markov chain approach detects malware with up to 89% F-measure and outperforms approaches based on API calls frequency. Massimo Ficco |
IC2E | 1 |
| 2019 | Could emerging fraudulent energy consumption attacks make the cloud infrastructure costs unsustainable?
Massimo Ficco |
Inf. Sci. | 1 |
| 2019 | Leaf: An open-source cybersecurity training platform for realistic edge-IoT scenarios
Massimo Ficco, Francesco Palmieri 0002 |
J. Syst. Archit. | 1 |
| 2018 | A coral-reefs and Game Theory-based approach for optimizing elastic cloud resource allocation
Massimo Ficco, Christian Esposito 0001, Francesco Palmieri 0002, Aniello Castiglione |
Future Gener. Comput. Syst. | 1 |
| 2018 | Aging-related performance anomalies in the apache storm stream processing system
Massimo Ficco, Roberto Pietrantuono, Stefano Russo 0001 |
Future Gener. Comput. Syst. | 1 |
| 2018 | Loss-Tolerant Event Communications Within Industrial Internet of Things by Leveraging on Game Theoretic IntelligenceabstractInternet of Things (IoT) is one of the key technologies paving the way for the next industrial revolution named as Industry 4.0, since it promises to realize smarter factories by optimizing costs and productivity. Traditionally, the adopted communication protocols among the sensors are required to manage the large scale of the infrastructure in terms on the high number of interconnected nodes and the massive volume of exchanged data. However, due to the key role of those Industrial IoT in exchanging business critical data, such protocols need to also provide high resiliency guarantees to the message exchange, with as few delivery misses as possible. The publish/subscribe interaction pattern and the protocol implementing it are a technically sound approach for achieving scalability and elasticity, thanks to their intrinsic decoupling among the interacting nodes. However, they are often unsuitable in their current form, because they provide only best-effort delivery guarantees, or they adopt naive solutions to achieve resilient communication, especially when wireless networks are used. This paper presents a clustered lightweight gossiping algorithm for resilient event based communications among the sensors, without requiring a pre-deployed brokering infrastructure supporting the adopted publish/subscribe protocol. A simulation-based assessment has been performed in order to empirically show the improvements in terms of successfully delivered notification without the excessive costs of the state-of-the-art solutions available in the literature. Christian Esposito 0001, Massimo Ficco, Aniello Castiglione, Francesco Palmieri 0002, Huimin Lu 0001 |
IEEE Internet Things J. | 2 |
| 2018 | Building a network embedded FEC protocol by using game theory
Christian Esposito 0001, Arcangelo Castiglione, Francesco Palmieri 0002, Massimo Ficco |
Inf. Sci. | 4 |
| 2018 | Event-based sensor data exchange and fusion in the Internet of Things environments
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco, Ciprian Dobre, George V. Iordache, Florin Pop |
J. Parallel Distributed Comput. | 4 |
| 2018 | A scalable distributed machine learning approach for attack detection in edge computing environments
Rafal Kozik, Michal Choras, Massimo Ficco, Francesco Palmieri 0002 |
J. Parallel Distributed Comput. | 3 |
| 2017 | Improving the gossiping effectiveness with distributed strategic learning (Invited paper)
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco |
Future Gener. Comput. Syst. | 4 |
| 2017 | Trust management for distributed heterogeneous systems by using linguistic term sets and hierarchies, aggregation operators and mechanism design
Christian Esposito 0001, Aniello Castiglione, Francesco Palmieri 0002, Massimo Ficco |
Future Gener. Comput. Syst. | 4 |
| 2017 | Optimized task allocation on private cloud for hybrid simulation of large-scale critical systems
Massimo Ficco, Beniamino Di Martino, Roberto Pietrantuono, Stefano Russo 0001 |
Future Gener. Comput. Syst. | 1 |
| 2016 | An HLA-based framework for simulation of large-scale critical systemsabstractSummary Evaluating the dependability of large‐scale critical infrastructures is a very difficult task that requires sophisticated modeling practices and experimentation environments/infrastructures. In particular, simulation of complex distributed systems require the integration of several different simulation tools and real‐time prototypes or emulated subsystems, which have to inter‐operate in a coordinated way. This paper presents a framework integrating simulation and emulation‐based subsystems, which is able to provide greater realism of the scenario under test. However, integrating simulation and emulation is a challenging issue because of the different time domains and to the communication overhead between the different time models, as well as to the large number of involved entities. Therefore, the high level architecture has been used to perform integration in a robust and standardized scenario. A cloud‐based virtualization platform has been adopted in order to reproduce complex system architectures on an elastic and adaptive locally controlled testbed. Copyright © 2015 John Wiley & Sons, Ltd. Massimo Ficco, Giovanni Avolio, Francesco Palmieri 0002, Aniello Castiglione |
Concurr. Comput. Pract. Exp. | 1 |
| 2016 | Using multi-objective metaheuristics for the optimal selection of positioning systems
Massimo Ficco, Roberto Pietrantuono, Stefano Russo 0001 |
Soft Comput. | 1 |
| 2016 | Smart Cloud Storage Service Selection Based on Fuzzy Logic, Theory of Evidence and Game TheoryabstractCloud platforms encompass a large number of storage services that can be used to manage the needs of customers. Each of these services, offered by a different provider, is characterized by specific features, limitations and prices. In presence of multiple options, it is crucial to select the best solution fitting the customer requirements in terms of quality of service and costs. Most of the available approaches are not able to handle uncertainty in the expression of subjective preferences from customers, and can result in wrong (or sub-optimal) service selections in presence of rational/selfish providers, exposing untrustworthy indications concerning the quality of service levels and prices associated to their offers. In addition, due to its multi-objective nature, the optimal service selection process results in a very complex task to be managed, when possible, in a distributed way, for well-known scalability reasons. In this work, we aim at facing the above challenges by proposing three novel contributions. The fuzzy sets theory is used to express vagueness in the subjective preferences of the customers. The service selection is resolved with the distributed application of fuzzy inference or Dempster-Shafer theory of evidence. The selection strategy is also complemented by the adoption of a game theoretic approach for promoting truth-telling ones among service providers. We present empirical evidence of the proposed solution effectiveness through properly crafted simulation experiments. Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione |
IEEE Trans. Computers | 2 |
| 2015 | Modeling security requirements for cloud-based system developmentabstractSummary The Cloud Computing paradigm provides a new model for the more flexible utilization of computing and storage services. However, such enhanced flexibility, which implies outsourcing the data and business applications to a third party, may introduce critical security issues. Therefore, there is a clear necessity of new security paradigms able to face all the problems introduced by the cloud approach. Although, in the last years, several solutions have been proposed, the implementation of secure cloud applications and services is still a complex and far from consolidated task. Starting from these considerations, this work fosters the development of a methodology that considers security concerns as an integral part of cloud‐based applications design and implementation. Accordingly, we present a set of stereotypes that defines a vocabulary for annotating Unified Modeling Language based models with information relevant for integrating the specification of security requirements into cloud architectures. This approach can be used to significantly improve productivity and overall success in the development of secure distributed cloud applications and systems. Copyright © 2014 John Wiley & Sons, Ltd. Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione |
Concurr. Comput. Pract. Exp. | 1 |
| 2015 | A knowledge-based platform for Big Data analytics based on publish/subscribe services and stream processing
Christian Esposito 0001, Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione |
Knowl. Based Syst. | 2 |
| 2015 | Stealthy Denial of Service Strategy in Cloud ComputingabstractThe success of the cloud computing paradigm is due to its on-demand, self-service, and pay-by-use nature. According to this paradigm, the effects of Denial of Service (DoS) attacks involve not only the quality of the delivered service, but also the service maintenance costs in terms of resource consumption. Specifically, the longer the detection delay is, the higher the costs to be incurred. Therefore, a particular attention has to be paid for stealthy DoS attacks. They aim at minimizing their visibility, and at the same time, they can be as harmful as the brute-force attacks. They are sophisticated attacks tailored to leverage the worst-case performance of the target system through specific periodic, pulsing, and low-rate traffic patterns. In this paper, we propose a strategy to orchestrate stealthy attack patterns, which exhibit a slowly-increasing-intensity trend designed to inflict the maximum financial cost to the cloud customer, while respecting the job size and the service arrival rate imposed by the detection mechanisms. We describe both how to apply the proposed strategy, and its effects on the target system deployed in the cloud. Massimo Ficco, Massimiliano Rak |
IEEE Trans. Cloud Comput. | 1 |
| 2015 | Energy-oriented denial of service attacks: an emerging menace for large cloud infrastructures
Francesco Palmieri 0002, Sergio Ricciardi, Ugo Fiore, Massimo Ficco, Aniello Castiglione |
J. Supercomput. | 4 |
| 2014 | Supporting Development of Certified Aeronautical Components by Applying Text Analysis TechniquesabstractSoftware certification is one of the major issue in the aeronautical domain. Therefore, in order to support the development of certifiable software components, Text Analysis has been adopted to support the quality assurance team to quick define a map of applicable standards and guidelines to accomplish certification needs. A specific certification tool has been implemented in order to support the search of certification material closer to a certifiable industry product, reducing the development effort of innovative product. Gaetano Zazzaro, Gabriella Gigante, E. Zaccariello, Massimo Ficco, Beniamino Di Martino |
CISIS | 4 |
| 2014 | Hybrid indoor and outdoor location services for new generation mobile terminals
Massimo Ficco, Francesco Palmieri 0002, Aniello Castiglione |
Pers. Ubiquitous Comput. | 1 |
| 2014 | Calibrating Indoor Positioning Systemswith Low EffortsabstractRecently, the positioning techniques based on the IEEE 802.11 signal strength are becoming the dominant solutions in the mobile device localization within indoor scenarios. Such solutions are characterized by two main pitfalls that compromise their effective usage in real application environments. First, during the calibration, a large amount of manual effort is required for acquiring a massive collection of training samples. Second, the positioning accuracy is directly related to the deployment of the wireless access points into the workspace, which is extremely time-consuming and requires human intervention. This paper presents an approach to reduce the manual calibration and to optimize the positioning accuracy, by selecting the best deployment schema of the wireless access points. The approach has been implemented in a tool, which uses an analytical signal propagation model to build the radio map of a given workspace, and exploits a multi-objective genetic algorithm to identify the best access points placement pattern that fits the required accuracy. A detailed experimental campaign is presented in order to show the benefits achievable by the proposed approach. Massimo Ficco, Christian Esposito 0001, Aniello Napolitano |
IEEE Trans. Mob. Comput. | 1 |
| 2012 | Intrusion Tolerance in Cloud Applications: The mOSAIC ApproachabstractCloud Computing is a recognized emerging solution for building Internet applications, which founds on delegation of every kind of resources to the network and on a pay-per-use business model. Cloud application, which runs consuming Cloud resources offered by Cloud Providers, offers open interfaces to their users, which access them from Internet and are often prone to Denial of Services attacks. This work focuses on the mosaic approach for development of Cloud applications, which offers a solution for gathering resources from many different providers. It shows how it is possible to enrich the mosaic platform with tools that, in a simple and transparent way, protect mosaic Cloud application from some well known Denial of Services attacks. The paper focuses on a single kind of attacks, called Deeply-Nested XML, in order to show the proposed approach and offer some preliminary results, which demonstrate the validity of the solution proposed. Massimo Ficco, Massimiliano Rak |
CISIS | 1 |
| 2012 | Intrusion Tolerance as a Service - A SLA-based Solution
Massimiliano Rak, Massimo Ficco |
CLOSER | 2 |
| 2012 | Simulation and Support of Critical Activities by Mobile Agents in Pervasive and Ubiquitous ScenariosabstractMany contexts of every-day life are characterized by pervasiveness and ubiquity of embedded systems. These features can be exploited to support people in different scenarios, such as emergency situations and post disaster management. In this paper, we propose an agent-based approach to assist and simulate human critical activities in such scenarios. We propose a rule-based solution, which is implemented as a decentralized solution, which delegates the verification of rules to independent mobile agents. Agents are software components that interact with neighboring objects and react on the basis of the surrounding context. Moreover, a simulation tool is presented. It is used to model the remote scenario by collecting of context information from the field. It supports the on-line monitoring of the ongoing activities and the prediction of future situations. We present an implementation of the proposed solution to support and supervise human activities in real scenarios. Rocco Aversa, Beniamino Di Martino, Massimo Ficco, Salvatore Venticinque |
ISPA | 3 |
| 2012 | Intrusion Tolerance of Stealth DoS Attacks to Web Services
Massimo Ficco, Massimiliano Rak |
SEC | 1 |
| 2009 | Calibrating RSS-Based Indoor Positioning SystemsabstractLocation estimation based on received signal strength (RSS) is the prevalent method in indoor positioning. For RSS-based methods a massive collection of training RSS samples is needed to calibrate the positioning system and to achieve a high positioning quality. The quality of these methods is directly related to the placement of the wireless sensors in the workspace and the radio map used to compute the user location. Traditionally deploying the reference points and building the radio map require human intervention and are extremely time-consuming. In this paper we aim to reduce these manual calibration efforts. We propose an automatic approach both to build a radio map in the given environment and to assess the best system calibration that fits the required positioning quality. The approach has been tested on the most used radio frequency-based technologies, i.e., IEEE 802.11 and Bluetooth. Christian Esposito 0001, Domenico Cotroneo, Massimo Ficco |
WiMob | 3 |
| 2009 | A hybrid positioning system for technology-independent location-aware computingabstractAbstract Location‐aware computing is a form of context‐aware mobile computing that refers to the ability of providing users with services that depend on their position. Locating the user terminal, often called positioning, is essential in this form of computing. Towards this aim, several technologies exist, ranging from personal area networking, to indoor, outdoor, and up to geographic area systems. Developers of location‐aware software applications have to face with a number of design choices, that typically depend on the chosen technology. This work addresses the problem of easing the development of pull location‐aware applications, by allowing uniform access to multiple heterogeneous positioning systems. Towards this aim, the paper proposes an approach to structure location‐aware mobile computing systems in a way independent of positioning technologies. The approach consists in structuring the system into a layered architecture, that provides application developers with a standard Java Application Programming Interface (JSR‐179 API), and encapsulates location data management and technology‐specific positioning subsystems into lower layers with clear interfaces. In order to demonstrate the proposed approach we present the development of HyLocSys. It is an open hybrid software architecture designed to support indoor/outdoor applications, which allows the uniform (combined or separate) use of several positioning technologies. HyLocSys uses a hybrid data model, which allows the integration of different location information representations (using symbolic and geometric coordinates). Moreover, it allows support to handset‐ and infrastructure‐based positioning approaches while respecting the privacy of the user. The paper presents a prototypal implementation of HyLocSys for heterogeneous scenarios. It has been implemented and tested on several platforms and mobile devices. Copyright © 2009 John Wiley & Sons, Ltd. Massimo Ficco, Stefano Russo 0001 |
Softw. Pract. Exp. | 1 |