Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Roberto Tiella

dblp:50/4548 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 10 · 1 first-authorArtificial intelligence and machine learning · 1Security and privacy · 1Databases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
3 papers
Software testing · 49% Debugging and program repair · 33% Program verification · 10%
Network and information security
1 paper
Cryptographic protocols and secure computation · 100%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software testing
test generation
0.222014
Interpolated n-grams for model based testing · ICSE 2014
SBFR: A search based approach for reproducing failures of programs with grammar based input · ASE 2013
Software testing
model-based testing
0.212014
Interpolated n-grams for model based testing · ICSE 2014
Debugging and program repair
bug reproduction
0.212013
SBFR: A search based approach for reproducing failures of programs with grammar based input · ASE 2013
Debugging and program repair
fault localization
0.212013
SBFR: A search based approach for reproducing failures of programs with grammar based input · ASE 2013
Cryptographic protocols and secure computation
electronic voting
0.112009
Development, formal verification, and evaluation of an E-voting system with VVPAT · IEEE Trans. Inf. Forensics Secur. 2009
Program verification
model checking
0.112009
Development, formal verification, and evaluation of an E-voting system with VVPAT · IEEE Trans. Inf. Forensics Secur. 2009
Program synthesis and code generation
grammar-constrained generation
0.012013
SBFR: A search based approach for reproducing failures of programs with grammar based input · ASE 2013
Requirements engineering and software design › user-centered design
participatory design
0.012009
Development, formal verification, and evaluation of an E-voting system with VVPAT · IEEE Trans. Inf. Forensics Secur. 2009

Methods — techniques the papers use, named apart from their topics

participatory design · 0.2model checking · 0.2formal methods · 0.2interpolated n-grams · 0.2finite-state machine model · 0.2search-based software engineering · 0.2genetic programming · 0.2
YearPublicationVenuePosition
2017 Automatic generation of opaque constants based on the k-clique problem for resilient data obfuscation
abstract
Data obfuscations are program transformations used to complicate program understanding and conceal actual values of program variables. The possibility to hide constant values is a basic building block of several obfuscation techniques. For example, in XOR Masking a constant mask is used to encode data, but this mask must be hidden too, in order to keep the obfuscation resilient to attacks. In this paper, we present a novel technique based on the k-clique problem, which is known to be NP-complete, to generate opaque constants, i.e. values that are difficult to guess by static analysis. In our experimental assessment we show that our opaque constants are computationally cheap to generate, both at obfuscation time and at runtime. Moreover, due to the NP-completeness of the k-clique problem, our opaque constants can be proven to be hard to attack with state-of-the-art static analysis tools.
Roberto Tiella, Mariano Ceccato
SANER1
2017 Generating valid grammar-based test inputs by means of genetic programming and annotated grammars
Fitsum Meshesha Kifetew, Roberto Tiella, Paolo Tonella
Empir. Softw. Eng.2
2016 Assessment of Source Code Obfuscation Techniques
abstract
Obfuscation techniques are a general category of software protections widely adopted to prevent malicious tampering of the code by making applications more difficult to understand and thus harder to modify. Obfuscation techniques are divided in code and data obfuscation, depending on the protected asset. While preliminary empirical studies have been conducted to determine the impact of code obfuscation, our work aims at assessing the effectiveness and efficiency in preventing attacks of a specific data obfuscation technique - VarMerge. We conducted an experiment with student participants performing two attack tasks on clear and obfuscated versions of two applications written in C. The experiment showed a significant effect of data obfuscation on both the time required to complete and the successful attack efficiency. An application with VarMerge reduces by six times the number of successful attacks per unit of time. This outcome provides a practical clue that can be used when applying software protections based on data obfuscation.
Alessio Viticchié, Leonardo Regano, Marco Torchiano, Cataldo Basile, Mariano Ceccato, Paolo Tonella, Roberto Tiella
SCAM7
2014 Interpolated n-grams for model based testing
abstract
Models - in particular finite state machine models - provide an invaluable source of information for the derivation of effective test cases. However, models usually approximate part of the program semantics and capture only some of the relevant dependencies and constraints. As a consequence, some of the test cases that are derived from models are infeasible.
Paolo Tonella, Roberto Tiella, Duy Cu Nguyen
ICSE2
2014 A Multi-objective Approach to Business Process Repair
Chiara Di Francescomarino, Roberto Tiella, Chiara Ghidini, Paolo Tonella
ICSOC2
2014 Reproducing Field Failures for Programs with Complex Grammar-Based Input
abstract
To isolate and fix failures that occur in the field, after deployment, developers must be able to reproduce and investigate such failures in-house. In practice, however, bug reports rarely provide enough information to recreate field failures, thus making in-house debugging an arduous task. This task becomes even more challenging for programs whose input must adhere to a formal specification, such as a grammar. To help developers address this issue, we propose an approach for automatically generating inputs that recreate field failures in-house. Given a faulty program and a field failure for this program, our approach exploits the potential of grammar-guided genetic programming to iteratively find legal inputs that can trigger the observed failure using a limited amount of runtime data collected in the field. When applied to 11 failures of 5 real-world programs, our approach was able to reproduce all but one of the failures while imposing a limited amount of overhead.
Fitsum Meshesha Kifetew, Wei Jin 0001, Roberto Tiella, Alessandro Orso, Paolo Tonella
ICST3
2014 Semantic-Based Process Analysis
Chiara Di Francescomarino, Francesco Corcoglioniti, Mauro Dragoni, Piergiorgio Bertoli, Roberto Tiella, Chiara Ghidini, Michele Nori, Marco Pistore
ISWC (2)5
2014 Combining Stochastic Grammars and Genetic Programming for Coverage Testing at the System Level
Fitsum Meshesha Kifetew, Roberto Tiella, Paolo Tonella
SSBSE2
2013 SBFR: A search based approach for reproducing failures of programs with grammar based input
abstract
Reproducing field failures in-house, a step developers must perform when assigned a bug report, is an arduous task. In most cases, developers must be able to reproduce a reported failure using only a stack trace and/or some informal description of the failure. The problem becomes even harder for the large class of programs whose input is highly structured and strictly specified by a grammar. To address this problem, we present SBFR, a search-based failure-reproduction technique for programs with structured input. SBFR formulates failure reproduction as a search problem. Starting from a reported failure and a limited amount of dynamic information about the failure, SBFR exploits the potential of genetic programming to iteratively find legal inputs that can trigger the failure.
Fitsum Meshesha Kifetew, Wei Jin 0001, Roberto Tiella, Alessandro Orso, Paolo Tonella
ASE3
2012 Crawlability Metrics for Web Applications
abstract
Automated web crawlers can be used to explore and exercise portions of a web application under test. However, the possibility to achieve full exploration of a web application through automated crawling is severely limited by the choice of the input values submitted with forms. Depending on the crawler's capabilities, a larger or smaller portion of web application will be automatically explored. In this paper, we introduce web crawl ability metrics to quantify properties of application pages and forms that affect crawl ability. Moreover, we show that our metrics can be used to identify the boundaries between those parts of the application that can be successfully crawled automatically and those parts that will require manual intervention or other crawl ability support. We have validated our crawl ability metrics on real web applications, for which low crawl ability was indeed associated with the existence of pages never exercised during automated crawling.
Nadia Alshahwan, Mark Harman, Alessandro Marchetto 0001, Roberto Tiella, Paolo Tonella
ICST4
2011 Crawlability metrics for automated web testing
Alessandro Marchetto 0001, Roberto Tiella, Paolo Tonella, Nadia Alshahwan, Mark Harman
Int. J. Softw. Tools Technol. Transf.2
2009 Development, formal verification, and evaluation of an E-voting system with VVPAT
abstract
The use of new technologies to support voting has been and is the subject of great debate. Several people advocate the benefits it can bring-such as improved speed and accuracy in counting, accessibility, voting from home-and as many are concerned with the risks it poses, such as unequal access (digital divide), violation to secrecy and anonymity, alteration of the results of an election (because of malicious attacks, bad design/coding, or procedural weaknesses). The attitude of different governments towards electronic voting (e-voting) varies accordingly. In this paper, we present the activities related to the development and formal verification of an e-voting system, called ProVotE. ProVotE is an end-to-end e-voting system with a voter verified paper audit trial, developed within the framework of a larger initiative whose goal is assessing the feasibility of introducing e-voting in the Autonomous Province of Trento. ProVotE has been used in trials and elections with legal value in Italy. What we believe to be of interest is the approach we took for its development, which has been based on a participatory design for the definition of the voter interface, on the usage of formal methods and model checking for the validation of the core logic of the machine, on open source components, and on the formal analysis of some critical procedures related to the usage of the machine during the election.
Adolfo Villafiorita, Komminist Weldemariam, Roberto Tiella
IEEE Trans. Inf. Forensics Secur.3