Claudio A. Ardagna

dblp:62/575 · also Claudio Agostino Ardagna · DBLP profile ↗
← Back
77ranked-venue papers
37as first author
29since 2021 · last 2026
0000-0001-7426-4795ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 19 · 9 first-author · 12 since 2021Security and privacy · 17 · 15 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 5 first-author · 3 since 2021Systems, architecture and hardware · 9 · 3 first-author · 5 since 2021Computer networks · 8 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 7 · 3 first-authorArtificial intelligence and machine learning · 2 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Non-functional certification of edge-computing satellite systems
abstract
Satellite telecommunication networks are playing an increasingly pivotal role in modern communication infrastructures, owing to their expansive coverage, high reliability, and growing capabilities in computing, storage, and bandwidth. In response to evolving market demands, mobile network operators are progressively integrating satellite systems with edge-cloud computing platforms to deliver advanced networking functionalities within a unified architecture. This integration places strong demands on the non-functional assessment (e.g., reliability, availability, and resource efficiency) of satellite-based edge nodes, introducing unprecedented challenges due to their unique operational constraints. In this paper, we propose a lightweight certification framework tailored for satellite computing systems, designed to assess and validate the non-functional posture of satellite edge networks. Our approach explicitly addresses the distinctive characteristics of satellite environments, including intermittent connectivity and constrained resource availability. We validate the proposed scheme through a realistic testbed implementation, modeling a 5G-enabled satellite edge node based on the Tiansuan satellite constellation, an experimental platform jointly developed by Beijing University of Posts and Telecommunications, Spacety, and Peking University.
Filippo Berto, Marco Anisetti, Qiyang Zhang 0001, Shangguang Wang, Claudio A. Ardagna
Comput. Networks5
2026 Vulnerability-Aware Secure Service Deployment in Cloud-Edge Continuum
abstract
Software weaknesses and vulnerabilities are continuously discovered and rapidly evolving. Their direct and indirect interference with the business process workflow execution is neither fully understood nor addressed by the current literature. The strict control of the vulnerability footprint of the landing platform before cloud/web service workflow execution is nowadays largely used as a prevention measure in order to improve execution trustworthiness. The vulnerability footprint governance is exacerbated by the cloud, where a common execution platform hosting (vulnerable) services is shared between different tenants. The paper proposes a service workflow deployment solution tailored for Edge-Cloud Continuum, made of different landing platforms showing different peculiarities. The proposed solution is capable of finding a suitable deployment recipe for a given workflow by i) evaluating the vulnerability footprint of each platform, ii) computing the set of candidate deployment platforms, iii) finding the optimal deployment solution, and iv) migrating already deployed workflows in case the vulnerability requirement is no longer satisfied. Each workflow can be associated with a set of requirements to be satisfied by our deployment solution, like the maximum level of vulnerability footprint accepted. Each workflow deployment contributes to the vulnerability footprint of the landing platform involved.
Ruslan Bondaruc, Nicolas Schnepf, Rémi Badonnel, Claudio A. Ardagna, Marco Anisetti
IEEE Trans. Netw. Serv. Manag.4
2025 Message from the Congress Program Chairs
abstract
We are delighted to welcome all participants to the 2025 IEEE World Congress on Services (IEEE SERVICES 2025), which is taking place in the beautiful city of Helsinki, Finland. To support the services community of researchers and practitioners around the world, IEEE SERVICES 2025 is held in hybrid mode.
Claudio A. Ardagna, Qiang He 0001, Tevfik Kosar
SSE1
2025 Message from the Congress Program Chairs
abstract
We are delighted to welcome all participants to the 2025 IEEE World Congress on Services (IEEE SERVICES 2025), which is taking place in the beautiful city of Helsinki, Finland. To support the services community of researchers and practitioners around the world, IEEE SERVICES 2025 is held in hybrid mode.
Claudio A. Ardagna, Qiang He 0001, Tevfik Kosar
ICWS1
2025 A Framework for Data Quality and Protection Management in Service-Based Data Pipelines
Antongiacomo Polimeno, Marco Luzzara, Marco Anisetti, Claudio A. Ardagna, Chirine Ghedira
ICWS4
2025 ML Assurance in 6G-Enabled Edge-Cloud Continuum Workflows
abstract
The modern edge-cloud continuum data intensive workflows are increasingly based on 6G edge nodes in order to spread their diffusion relying on public network and enhanced by the use of machine learning (ML) models in order to extend their capabilities. Data intensive workflows are also glowingly used in critical scenarios such as health and IoT. In these scenarios, guarantees on the model prediction quality and on the model non-functional properties (e.g., model confidentiality), are nowadays requested in order to comply with regulations such as the EU AI Act. Although the traditional CIA (Confidentiality, Integrity, Availability) triad are largely considered as the minimal non-functional properties to be guaranteed for a given system, they cannot be applied as such in the context of ML models. In this paper we identify the shortcomings of the conventional definition of CIA, provides novel ML-specific definitions for the CIA non-functional properties and develops an assurance methodology to evaluate them on the target models and provide relevant guarantees. The paper presents an experimental evaluation based on a realistic MLOps pipeline aimed to demonstrate its feasibility and effectiveness and is based on the novel definition of ML model integrity Non-Functional Property.
Marco Anisetti, Claudio A. Ardagna, Filippo Berto, Alex Della Bruna
WCNC2
2025 Protecting machine learning from poisoning attacks: A risk-based approach
abstract
The ever-increasing interest in and widespread diffusion of Machine Learning (ML)-based applications has driven a substantial amount of research into offensive and defensive ML. ML models can be attacked from different angles: poisoning attacks, the focus of this paper, inject maliciously crafted data points in the training set to modify the model behavior; adversarial attacks maliciously manipulate inference-time data points to fool the ML model and drive the prediction of the ML model according to the attacker’s objective. Ensemble-based techniques are among the most relevant defenses against poisoning attacks and replace the monolithic ML model with an ensemble of ML models trained on different (disjoint) subsets of the training set. They assign data points to the training sets of the models in the ensemble (routing) randomly or using a hash function, assuming that evenly distributing poisoned data points positively influences ML robustness. Our paper departs from this assumption and implements a risk-based ensemble technique where a risk management process is used to perform a smart routing of data points to the training sets. An extensive experimental evaluation demonstrates the effectiveness of the proposed approach in terms of its soundness, robustness, and performance.
Nicola Bena, Marco Anisetti, Ernesto Damiani, Chan Yeob Yeun, Claudio A. Ardagna
Comput. Secur.5
2025 Continuous Management of Machine Learning-Based Application Behavior
abstract
Modern applications are increasingly driven by Machine Learning (ML) models whose non-deterministic behavior is affecting the entire application life cycle from design to operation. The pervasive adoption of ML is urgently calling for approaches that guarantee a stable non-functional behavior of ML-based applications over time and across model changes. To this aim, non-functional properties of ML models, such as privacy, confidentiality, fairness, and explainability, must be monitored, verified, and maintained. Existing approaches mostly focus oni)implementing solutions for classifier selection according to the functional behavior of ML models,ii)finding new algorithmic solutions, such as continuous re-training. In this paper, we propose a multi-model approach that aims to guarantee a stable non-functional behavior of ML-based applications. An architectural and methodological approach is provided to compare multiple ML models showing similar non-functional properties and select the model supporting stable non-functional behavior over time according to (dynamic and unpredictable) contextual changes. Our approach goes beyond the state of the art by providing a solution that continuously guarantees a stable non-functional behavior of ML-based applications, is ML algorithm-agnostic, and is driven by non-functional properties assessed on the ML models themselves. It consists of a two-step process working during application operation, wheremodel assessmentverifies non-functional properties of ML models trained and selected at development time, andmodel substitutionguarantees continuous and stable support of non-functional properties. We experimentally evaluate our solution in a real-world scenario focusing on non-functional property fairness.
Marco Anisetti, Claudio A. Ardagna, Nicola Bena, Ernesto Damiani, Paolo G. Panero
IEEE Trans. Serv. Comput.2
2024 Decolonizing Federated Learning: Designing Fair and Responsible Resource Allocation
abstract
This position paper explores the challenges, existing solutions, and open issues related to resource allocation in federated learning environments. The focus is on how to allocate resources effectively while adhering to service level objectives (SLOs) and fairness requirements, which include factors such as server location, data provenance, energy consumption, sovereignty, carbon footprint, and economic cost. The goal is to optimise resource distribution across different stages of the federated learning process within a given architecture, ensuring that these fairness criteria are integrated into the allocation strategy. This approach aligns with decolonial methodologies that seek to offer more sustainable and equitable alternatives to the resource-intensive artificial intelligence processes prevalent today.
Genoveva Vargas-Solar, Nadia Bennani, Javier A. Espinosa-Oviedo, Andrea Mauri 0001, José-Luis Zechinelli-Martini, Barbara Catania, Claudio A. Ardagna, Nicola Bena
AICCSA7
2024 MUSA: A Platform for Data-Intensive Services in Edge-Cloud Continuum
Marco Anisetti, Claudio A. Ardagna, Massimo Banzi, Filippo Berto, Ruslan Bondaruc, Ernesto Damiani, Alessandro Pedretti, Arianna Pisati, Antonio Retico
AINA (5)2
2024 A Methodology for Web Cache Deception Vulnerability Discovery
abstract
In recent years, the use of caching techniques in web applications has increased significantly, in line with their expanding user base. The logic of web caches is closely tied to the application logic, and misconfigurations can lead to security risks, including the unauthorized access of private information and session hijacking. In this study, we examine Web Cache Deception as a technique for attacking web applications. We develop a solution for discovering vulnerabilities that expands upon and encompasses prior research in the field. We conducted an experimental evaluation of the attack’s efficacy against real-world targets, and present a new attack vector via web-client-based email services.
Filippo Berto, Francesco Minetti, Claudio A. Ardagna, Marco Anisetti
CLOSER3
2024 Toward Efficient Satellite Computing Through Adaptive Compression
abstract
The rapid development of Low Earth Orbit (LEO) satellite constellations offers significant potential for in-orbit services, particularly in mitigating the impact of sudden natural disasters. However, the massive data collected by these satellites are often large and severely constrained by limited transmission capabilities when sending data to the ground. Satellite computing, which utilizes onboard computational capacity to process data before transmission, presents a promising solution to alleviate the downlink burden. Nonetheless, this paradigm introduces another bottleneck: limited onboard computing capacity, resulting in slow in-orbit processing and poor results. Current satellite computing systems struggle to efficiently address both data transmission and computing bottlenecks, particularly for urgent disaster services that demand accurate and timely results. Thus, we introduce an efficient satellite computing system designed to jointly mitigate these bottlenecks, thereby providing better service. The core idea is to utilize onboard computing capacity for swift in-orbit annotation of image regions, enabling adaptive compression and download based on annotation confidence and perceived downlink availability. Once the data is downloaded, image restoration and re-inference are performed on the ground to enhance accuracy. Compared to satellite-only inference, our system demonstrates an average improvement in inference accuracy of 3.8%. Furthermore, compared to ground-only inference, with only a 2.8% accuracy loss, our system achieves a 38.4% reduction in response time and saves 71.6% of downlink volume on average.
Chen Yang 0043, Qibo Sun, Qiyang Zhang 0001, Claudio A. Ardagna, Shangguang Wang, Mengwei Xu 0001
IEEE Trans. Serv. Comput.5
2023 Non-Functional Certification of Modern Distributed Systems: A Research Manifesto
abstract
The huge progress of ICT is radically changing distributed systems at their roots, modifying their operation and engineering practices and introducing new non-functional (e.g., security and safety) risks. These risks are amplified by the crucial role played by machine learning, on one side, and by the pervasive involvement of users in the system operation, on the other side. Certification techniques have been largely adopted to reduce the above risks, though the recent evolution of distributed systems towards cloud-edge, IoT, 5G, and machine learning severely hindered certification diffusion and quality. The need of new certification techniques that prove compliance of distributed systems against non-functional requirements arises and is often pushed by strict laws and regulations. In this paper, we envision a research manifesto for non-functional certification of modern distributed systems that paves the way for the wide adoption of certification in the real world, also in those domains where certification is not mandatory. Its ultimate goal is to lead to a trustworthy and adaptive ecosystem based on a cost-effective, non-functional certification, where modern system development, assessment, and management are not only ruled by functional requirements. The manifesto discusses the research challenges, a roadmap built on 6 research directions, and a concrete implementation timeline for the roadmap.
Claudio A. Ardagna, Nicola Bena
SSE1
2023 Transparency-based reconnaissance for APT attacks
abstract
Transparency is a fundamental administrative principle for public institutions. One of its main implementations is the publication of goods and service acquisition tenders, as prescribed by EU and national legislation. This need of transparency can however undermine the security of public institutions, which are disseminating information that could be leveraged by advanced threat actors to bring disruptive attacks. In this paper, we analyse how threat actors can extract useful information from this publicly available information, taking advantage from transparency. We introduce a new technique named transparency-based reconnaissance, which implements a passive recognition process using transparency information published under law requirements. To better highlight the value of the gathered data, we experiment its effectiveness by simulating a transparency-based reconnaissance run against an Italian public institution, obtaining complete technological and supply chain inventories. The collected inventories enabled the creation of an unsophisticated malware bypassing the defences in place, along with a weaponization and delivery strategy. Finally, we propose a list of potential countermeasure areas, both technical and organizational, to protect information while still safeguarding transparency through a graduated approach.
Alessio Rugo, Claudio A. Ardagna
COMPSAC2
2023 Continuous Certification of Non-functional Properties Across System Changes
Marco Anisetti, Claudio A. Ardagna, Nicola Bena
ICSOC (1)2
2023 Lightweight Behavior-Based Malware Detection
Marco Anisetti, Claudio A. Ardagna, Nicola Bena, Vincenzo Giandomenico, Gabriele Gianini
MEDES2
2023 An assurance process for Big Data trustworthiness
abstract
Modern (industrial) domains are based on large digital ecosystems where huge amounts of data and information need to be collected, shared, and analyzed by multiple actors working within and across organizational boundaries. This data-driven ecosystem poses strong requirements on data management and data analysis, as well as on data protection and system trustworthiness. However, although Big Data has reached its functional maturity and represents a key enabler for enterprises to compete in the global market, the assurance and trustworthiness of Big Data computations (e.g., security, privacy) are still in their infancy. While functionally appealing, Big Data does not provide a transparent environment with clear non-functional properties, impairing the users’ ability to evaluate its behavior and clashing with modern data-privacy regulations. In this paper, we present a novel assurance process for Big Data, which evaluates the Big Data pipelines, and the Big Data ecosystem underneath, to provide a comprehensive measure of their trustworthiness. To the best of our knowledge, this approach is the first attempt to address the general problem of Big Data trustworthiness in an holistic way. We experimentally evaluate our solution in a real Big Data Analytics-as-a-Service environment, first presenting a detailed walkthrough evaluation, and then showing its feasibility and negligible performance overhead (i.e., approx 1 min).
Marco Anisetti, Claudio A. Ardagna, Filippo Berto
Future Gener. Comput. Syst.2
2023 Multi-Dimensional Certification of Modern Distributed Systems
abstract
The cloud computing has deeply changed how distributed systems are engineered, leading to the proliferation of ever/evolving and complex environments, where legacy systems, microservices, and nanoservices coexist. These services can severely impact on individuals' security and safety, introducing the need of solutions that properly assess and verify their correct behavior. Security assurance stands out as the way to address such pressing needs, with certification techniques being used to certify that a given service holds some non/functional properties. However, existing techniques build their evaluation on software artifacts only, falling short in providing a thorough evaluation of the non/functional properties under certification. In this paper, we present a multi/dimensional certification scheme where additional dimensions model relevant aspects (e.g., programming languages and development processes) that significantly contribute to the quality of the certification results. Our multi/dimensional certification enables a new generation of service selection approaches capable to handle a variety of user's requirements on the full system life cycle, from system development to its operation and maintenance. The performance and the quality of our approach are thoroughly evaluated in several experiments.
Marco Anisetti, Claudio A. Ardagna, Nicola Bena
IEEE Trans. Serv. Comput.2
2023 On the Robustness of Random Forest Against Untargeted Data Poisoning: An Ensemble-Based Approach
abstract
Machine learning is becoming ubiquitous. From finance to medicine, machine learning models are boosting decision/making processes and even outperforming humans in some tasks. This huge progress in terms of prediction quality does not however find a counterpart in the security of such models and corresponding predictions, where perturbations of fractions of the training set (poisoning) can seriously undermine the model accuracy. Research on poisoning attacks and defenses received increasing attention in the last decade, leading to several promising solutions aiming to increase the robustness of machine learning. Among them, ensemble-based defenses, where different models are trained on portions of the training set and their predictions are then aggregated, provide strong theoretical guarantees at the price of a linear overhead. Surprisingly, ensemble-based defenses, which do not pose any restrictions on the base model, have not been applied to increase the robustness of random forest models. The work in this paper aims to fill in this gap by designing and implementing a novel hash-based ensemble approach that protects random forest against untargeted, random poisoning attacks. An extensive experimental evaluation measures the performance of our approach against a variety of attacks, as well as its sustainability in terms of resource consumption and performance, and compares it with a traditional monolithic model based on random forest. A final discussion presents our main findings and compares our approach with existing poisoning defenses targeting random forests.
Marco Anisetti, Claudio A. Ardagna, Alessandro Balestrucci, Nicola Bena, Ernesto Damiani, Chan Yeob Yeun
IEEE Trans. Sustain. Comput.2
2022 Bridging the Gap Between Certification and Software Development
abstract
While certification is widely recognized as a means to increase system trustworthiness and reduce uncertainty in decision making, it faces severe challenges preventing a wider adoption thereof. Certification is not adequately planned and integrated within the development process, leading to suboptimal scenarios where certification introduces the need to further modify the developed system with high costs. We propose a methodology that bridges the gap between software development and certification processes. Our methodology automatically produces the certification requirements driving all steps of the development process, and maximizes the strength of certificates while taking costs under control. We formalize the above problem as a multi-objective mathematical program and solve it through a genetic algorithm. The proposed approach is tested in a real-world, cloud-based financial scenario at CaixaBank and its performance and quality is evaluated in a simulated scenario.
Claudio A. Ardagna, Nicola Bena, Ramon Martín de Pozuelo
ARES1
2022 A Security Certification Scheme for Information-Centric Networks
abstract
Information-Centric Networking is an emerging alternative to host-centric networking designed for large-scale content distribution and stricter privacy requirements. Recent research on Information-Centric Networking focused on the protection of the network from attacks targeting the content delivery protocols, while assuming genuine content can always be retrieved from trustworthy nodes. In this paper, we depart from the assumption of the trustworthiness of network nodes and propose a novel certification methodology for information-centric networks that supports continuous security verification of non-functional properties. Our methodology provides a complete and detailed view of the network security status, increasing the trustworthiness of the network and its services. The proposed approach builds on an enhanced certification model capturing the evolution of the system over time. It also defines certification services that fully integrate with existing networks to collect evidence on the target of certification and carry out the certification process. It finally proposes two certification processes, centralized and decentralized, balancing the impact on the network and the system performance. Efficiency, performance, and soundness of our approach are experimentally evaluated in a simulated Named Data Networking (NDN) network targeting property availability.
Marco Anisetti, Claudio A. Ardagna, Filippo Berto, Ernesto Damiani
IEEE Trans. Netw. Serv. Manag.2
2021 The Italian research on HPC key technologies across EuroHPC
abstract
High-Performance Computing (HPC) is one of the strategic priorities for research and innovation worldwide due to its relevance for industrial and scientific applications. We envision HPC as composed of three pillars: infrastructures, applications, and key technologies and tools. While infrastructures are by construction centralized in large-scale HPC centers, and applications are generally within the purview of domain-specific organizations, key technologies fall in an intermediate case where coordination is needed, but design and development are often decentralized. A large group of Italian researchers has started a dedicated laboratory within the National Interuniversity Consortium for Informatics (CINI) to address this challenge. The laboratory, albeit young, has managed to succeed in its first attempts to propose a coordinated approach to HPC research within the EuroHPC Joint Undertaking, participating in the calls 2019--20 to five successful proposals for an aggregate total cost of 95M€. In this paper, we outline the working group's scope and goals and provide an overview of the five funded projects, which become fully operational in March 2021, and cover a selection of key technologies provided by the working group partners, highlighting their usage development within the projects.
Marco Aldinucci, Giovanni Agosta, Antonio Andreini, Claudio A. Ardagna, Andrea Bartolini, Alessandro Cilardo, Biagio Cosenza, Marco Danelutto, Roberto Esposito, William Fornaciari, Roberto Giorgi, Davide Lengani, Raffaele Montella, Mauro Olivieri, Sergio Saponara, Daniele Simoni, Massimo Torquati
CF4
2021 An Assurance-Based Risk Management Framework for Distributed Systems
abstract
The advent of cloud computing and Internet of Things (IoT) has deeply changed the design and operation of IT systems, affecting mature concepts like trust, security, and privacy. The benefits in terms of new services and applications come at a price of new fundamental risks, and the need of adapting risk management frameworks to properly understand and address them. While research on risk management is an established practice that dates back to the 90s, many of the existing frameworks do not even come close to address the intrinsic complexity and heterogeneity of modern systems. They rather target static environments and monolithic systems thus undermining their usefulness in real-world use cases. In this paper, we present an assurance-based risk management framework that addresses the requirements of risk management in modern distributed systems. The proposed framework implements a risk management process integrated with assurance techniques. Assurance techniques monitor the correct behavior of the target system, that is, the correct working of the mechanisms implemented by the organization to mitigate the risk. Flow networks compute risk mitigation and retrieve the residual risk for the organization. The performance and quality of the framework are evaluated in a simulated industry 4.0 scenario.
Marco Anisetti, Claudio A. Ardagna, Nicola Bena, Andrea Foppiani
ICWS2
2021 Dynamic and Scalable Enforcement of Access Control Policies for Big Data
abstract
The conflict between the need of protecting and sharing data is hampering the spread of big data applications. Security and privacy assurance is required to protect data owners, while data access and sharing are fundamental to implement smart big data solutions. In this context, access control systems can assume a central role in balancing data protection and data sharing. However, existing access control solutions are not general and scalable enough to address the software and technological complexity of big data ecosystems, being unable to support such a dynamic and collaborative environment. In this paper, we propose an access control system that enforces access to data in a distributed, multi-party big data environment. It is based on data annotations and secure data transformations performed at ingestion time. We show the feasibility of our approach in the smart city domain using an Apache-based big data engine.
Marco Anisetti, Claudio A. Ardagna, Chiara Braghin, Ernesto Damiani, Antongiacomo Polimeno, Alessandro Balestrucci
MEDES2
2021 A trust assurance technique for Internet of things based on human behavior compliance
abstract
Summary The advent of the Internet of things (IoT) has radically changed the way in which computations and communications are carried out. People are just becoming another component of IoT environments, and in turn, IoT environments are becoming a mixture of platforms, software, services, things, and people. The price we pay for such dynamic and powerful environment is an intrinsic uncertainty and low trustworthiness due to its opaque perimeter, the multitude of different data sources with unknown providers, and uncertain responsibilities. Trustworthiness of observables collected by smart devices (from minuscle sensors to bigger machines) is fundamental to build a chain of trust on a decision process taken according to these observables. Some assurance solutions evaluate the quality of collected data, although they are difficult to apply in IoT environments for performance and cost reasons. In this paper, we take a different approach and put forward the idea that, in many cases, the behavior of people owning smart devices can contribute to the evaluation of the trustworthiness of collected data and, in turn, of the whole decision process. We therefore define an assurance methodology based on data analytics evaluating the compliance of people to behavioral policies. The more people behavior is compliant, the higher the trustworthiness of data collected through their smart devices.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Alessandro Sala
Concurr. Comput. Pract. Exp.2
2021 Editorial: Special issue on trusted Cloud-Edges computations
Claudio A. Ardagna, Mauro Conti, Ernesto Damiani, Chia-Mu Yu
Future Gener. Comput. Syst.1
2021 From Trustworthy Data to Trustworthy IoT: A Data Collection Methodology Based on Blockchain
abstract
Internet of Things (IoT) is composed of physical devices, communication networks, and services provided by edge systems and over-the-top applications. IoT connects billions of devices that collect data from the physical environment, which are pre-processed at the edge and then forwarded to processing services at the core of the infrastructure, on top of which cloud-based applications are built and provided to mobile end users. IoT comes with important advantages in terms of applications and added value for its users, making their world smarter and simpler. These advantages, however, are mitigated by the difficulty of guaranteeing IoT trustworthiness, which is still in its infancy. IoT trustworthiness is a must especially in critical domains (e.g., health, transportation) where humans become new components of an IoT system and their life is put at risk by system malfunctioning or breaches. In this article, we put forward the idea that trust in IoT can be boosted if and only if its automation and adaptation processes are based on trustworthy data. We therefore depart from a scenario that considers the quality of a single decision as the main goal of an IoT system and consider the trustworthiness of collected data as a fundamental requirement at the basis of a trustworthy IoT environment. We therefore define a methodology for data collection that filters untrusted data out according to trust rules evaluating the status of the devices collecting data and the collected data themselves. Our approach is based on blockchain and smart contracts and collects data whose trustworthiness and integrity are proven over time. The methodology balances trustworthiness and privacy and is experimentally evaluated in real-world and simulated scenarios using Hyperledger fabric blockchain.
Claudio A. Ardagna, Rasool Asal, Ernesto Damiani, Nabil El Ioini, Mehdi Elahi, Claus Pahl
ACM Trans. Cyber Phys. Syst.1
2021 Certification-Based Cloud Adaptation
abstract
Performance and dependability levels of cloud-based computations are difficult to guarantee by-design due to segregation of visibility and control between applications, data owners, and cloud providers. Lack of predictability increases users' uncertainty about the service levels they will actually achieve. Cloud tenants compete for shared resources/services at all layers of the cloud stack, and pose heterogeneous and conflicting non-functional requirements over them. These requirements have implications for platform and infrastructure layers, which have to be configured to satisfy inter-tenants requirements. We argue that adaptation techniques can play a crucial role in providing a reliable cloud, supporting definite behavior of applications and stable quality of service. Existing adaptation techniques however are unsuitable for cloud use, since they mostly focus on single tenancy, performance requirements, and are based on unverifiable evidence, which is collected in an untrusted way. In this paper, we propose a multi-tenant, general-purpose adaptation technique for the cloud, based on evidence collected by means of a trustworthy certification process. We depart from traditional heavy and comprehensive certification processes, such as ISO/IEC 27017, and consider a flexible and lightweight certification process for the cloud. It is based on authentic evidence and provides accountable validation on the compliance of a cloud-based system. Our approach adapts the cloud at all layers to maintain stable non-functional properties in certificates over time, by continuously verifying certificate validity. We assess the performance and quality of our adaptation approach in a wide range of settings.
Claudio A. Ardagna, Rasool Asal, Ernesto Damiani, Theodosis Dimitrakos, Nabil El Ioini, Claus Pahl
IEEE Trans. Serv. Comput.1
2021 Model-Based Big Data Analytics-as-a-Service: Take Big Data to the Next Level
abstract
The Big Data revolution promises to build a data-driven ecosystem where better decisions are supported by enhanced analytics and data management.However, major hurdles still need to be overcome on the road that leads to commoditization and wide adoption of Big Data Analytics (BDA).Big Data complexity is the first factor hampering the full potential of BDA.The opacity and variety of Big Data technologies and computations, in fact, make BDA a failure prone and resource-intensive process, which requires a trial-and-error approach.This problem is even exacerbated by the fact that current solutions to Big Data application development take a bottom-up approach, where the last technology release drives application development.Selection of the best Big Data platform, as well as of the best pipeline to execute analytics, represents then a deal breaker.In this paper, we propose a return to roots by defining a Model-Driven Engineering (MDE) methodology that supports automation of BDA based on model specification.Our approach lets customers declare requirements to be achieved by an abstract Big Data platform and smart engines deploy the Big Data pipeline carrying out the analytics on a specific instance of such platform.Driven by customers' requirements, our methodology is based on an OWL-S ontology of Big Data services and on a compiler transforming OWL-S service compositions in workflows that can be directly executed on the selected platform.The proposal is experimentally evaluated in a real-world scenario focusing on the threat detection system of SAP.
Claudio A. Ardagna, Valerio Bellandi, Michele Bezzi, Paolo Ceravolo, Ernesto Damiani, Cédric Hébert
IEEE Trans. Serv. Comput.1
2020 A Methodology for Non-Functional Property Evaluation of Machine Learning Models
abstract
The pervasive diffusion of Machine Learning (ML) in many critical domains and application scenarios has revolutionized implementation and working of modern IT systems. The behavior of modern systems often depends on the behavior of ML models, which are treated as black boxes, thus making automated decisions based on inference unpredictable. In this context, there is an increasing need of verifying the non-functional properties of ML models, such as, fairness and privacy, to the aim of providing certified ML-based applications and services. In this paper, we propose a methodology based on Multi-Armed Bandit for evaluating non-functional properties of ML models. Our methodology adopts Thompson sampling, Monte Carlo Simulation, and Value Remaining. An experimental evaluation in a real-world scenario is presented to prove the applicability of our approach in evaluating the fairness of different ML models.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Paolo G. Panero
MEDES2
2020 Certified Machine-Learning Models
Ernesto Damiani, Claudio A. Ardagna
SOFSEM2
2020 Special issue on Trusted Cloud-Edges Computations
Claudio A. Ardagna, Mauro Conti, Chia-Mu Yu
Future Gener. Comput. Syst.1
2020 Cost-effective deployment of certified cloud composite services
abstract
The advent of cloud computing has radically changed the concept of distributed environments, where services can now be composed and reused at high rates. Today, service composition in the cloud is driven by the need of providing stable QoS, where non-functional properties of composite services are proven over time and composite services continuously adapt to both functional and non-functional changes of the component services. This scenario introduces substantial costs on the cloud providers that go beyond the cost of deploying component services, and require to consider the costs of continuously verifying non-functional properties of composite and component services. In this paper, we propose a cost-effective approach to certification-based cloud service composition. This approach is based, on one side, on a portable certification process for the cloud evaluating non-functional properties of composite services and, on the other side, on a cost-evaluation methodology aimed to produce the service composition that minimizes the total cost paid by the cloud providers, taking into account both deployment and certification/verification costs. Our service composition approach is driven by certificates awarded to single services and by a fuzzy-based cost evaluation methodology, and assumes certified properties as must-have requirements for service selection and composition.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi, Gwanggil Jeon
J. Parallel Distributed Comput.2
2020 A Semi-Automatic and Trustworthy Scheme for Continuous Cloud Service Certification
abstract
Traditional assurance solutions for software-based systems rely on static verification techniques and assume continuous availability of trusted third parties. With the advent of cloud computing, these solutions become ineffective since services/applications are flexible, dynamic, and change at runtime, at high rates. Although several assurance approaches have been defined, cloud requires a step-change moving current assurance techniques to fully embrace the cloud peculiarities. In this paper, we provide a rigorous and adaptive assurance technique based on certification, towards the definition of a transparent and trusted cloud ecosystem. It aims to increase the confidence of cloud customers that every piece of the cloud (from its infrastructure to hosted applications) behaves as expected and according to their requirements. We first present a test-based certification scheme proving non-functional properties of cloud-based services. The scheme is driven by non-functional requirements defined by the certification authority and by a model of the service under certification. We then define an automatic approach to verification of consistency between requirements and models, which is at the basis of the chain of trust supported by the certification scheme. We also present a continuous certificate life cycle management process including both certificate issuing and its adaptation to address contextual changes. Finally, we describe our certification framework and an experimental evaluation of its performance, quality, applicability, and practical usability in a real industrial scenario, which considers Engineering Ingegneria Informatica S.p.A. ENGpay online payment system.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi
IEEE Trans. Serv. Comput.2
2019 A Methodology for Cross-Platform, Event-Driven Big Data Analytics-as-a-Service
abstract
The advent of Big Data has revolutionized the way in which data are collected, analyzed, and processed, becoming a pre-requisite for each enterprise that competes in the global market. In this respect, the commodization of Big Data analytics is an essential goal to be faced in the near future. Recently, some preliminary approaches have been presented mostly focusing on distributing Big Data platforms as a service, while less has been done on cross-platform Big Data analytics. In this paper, we propose a model-based methodology for Big Data Analytics-as-a-Service that extends existing techniques by supporting cross-communication between batch and stream processing, deployment on multiple platforms, and end-to-end verification against users' requirements.
Claudio A. Ardagna, Valerio Bellandi, Paolo Ceravolo, Ernesto Damiani, Rino Finazzo
IEEE BigData1
2019 A Continuous Certification Methodology for DevOps
abstract
The cloud paradigm has revolutionized the way in which software systems are designed, managed, and maintained. With the advent of the microservice architecture, this trend was brought to the extreme, pushing the whole software development process towards unification of software development (Dev) and software operation (Ops). This rapid evolution has not immediately found counterparts in assurance techniques, where the evaluation of the non-functional behavior of a software system and of the software development process are completely decoupled. In this paper, we put forward the idea that next-generation assurance techniques, and more specifically certification techniques, must evaluate a software system throughout the whole development process. To this aim, we define a continuous certification scheme for DevOps that evaluates the software artifacts produced at each stage of the development process. We then present the assurance framework managing our certification scheme and experimentally evaluate the continuous certification scheme in a real DevOps scenario.
Marco Anisetti, Claudio A. Ardagna, Filippo Gaudenzi, Ernesto Damiani
MEDES2
2019 Test-Based Security Certification of Composite Services
abstract
The diffusion of service-based and cloud-based systems has created a scenario where software is often made available as services, offered as commodities over corporate networks or the global net. This scenario supports the definition of business processes as composite services, which are implemented via either static or runtime composition of offerings provided by different suppliers. Fast and accurate evaluation of services’ security properties becomes then a fundamental requirement and is nowadays part of the software development process. In this article, we show how the verification of security properties of composite services can be handled by test-based security certification and built to be effective and efficient in dynamic composition scenarios. Our approach builds on existing security certification schemes for monolithic services and extends them towards service compositions. It virtually certifies composite services, starting from certificates awarded to the component services. We describe three heuristic algorithms for generating runtime test-based evidence of the composite service holding the properties. These algorithms are compared with the corresponding exhaustive algorithm to evaluate their quality and performance. We also evaluate the proposed approach in a real-world industrial scenario, which considers ENGpay online payment system of Engineering Ingegneria Informatica S.p.A. The proposed industrial evaluation presents the utility and generality of the proposed approach by showing how certification results can be used as a basis to establish compliance to Payment Card Industry Data Security Standard.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Gianluca Polegri
ACM Trans. Web2
2018 Semantic Support for Model Based Big Data Analytics-as-a-Service (MBDAaaS)
Domenico Redavid, Donato Malerba, Beniamino Di Martino, Antonio Esposito 0001, Claudio A. Ardagna, Valerio Bellandi, Paolo Ceravolo, Ernesto Damiani
CISIS5
2018 Moon Cloud: A Cloud Platform for ICT Security Governance
abstract
Cybersecurity is the second emergency in Europe just after the climate changes. Everyday most of the small, medium and big enterprises are under attack. This scenario requires, on one side, new security solutions protecting ICT systems against misbehaviors/malicious attacks and, on the other side, a continuous assurance process evaluating the system robustness against new threats. In this paper we present Moon Cloud, a Cloud PaaS solution providing customizable assurance based on compliance for ICT systems, including public and private cloud systems and IoT environments. We also present a concrete security assessment carried out in a real scenario.
Marco Anisetti, Claudio A. Ardagna, Filippo Gaudenzi, Ernesto Damiani, Nicla Diomede, Patrizio Tufarolo
GLOBECOM2
2018 Modeling time, probability, and configuration constraints for continuous cloud service certification
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Nabil El Ioini, Filippo Gaudenzi
Comput. Secur.2
2017 A Security Benchmark for OpenStack
abstract
The cloud computing paradigm entails a radical change in IT provisioning, which must be understood and correctly applied especially when security requirements are considered. Security requirements do not cover anymore just the application itself, but involve the whole cloud supply chain from the hosting infrastructure to the final applications. This scenario requires, on one side, new security mechanisms protecting the cloud against misbehaviors/malicious attacks and, on the other side, a continuous and adaptive assurance process evaluating the observed cloud security behavior against the expected one. In this paper, we focus on the evaluation of the security assurance of OpenStack, a major open source cloud infrastructure. We first define a security benchmark for OpenStack, inspired by Center for Internet Security (CIS) benchmark for cloud infrastructures. We then present a platform, called Moon Cloud, for cloud security assurance evaluation, showing an application of our benchmark and platform to the in-production OpenStack deployment of the University of Milan.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi
CLOUD2
2017 Toward Model-Based Big Data-as-a-Service: The TOREADOR Approach
Ernesto Damiani, Claudio A. Ardagna, Paolo Ceravolo, Nello Scarabottolo
ADBIS2
2017 Anonymous end-to-end communications in adversarial mobile clouds
Claudio A. Ardagna, Kanishka Ariyapala, Mauro Conti, Maria Cristina Pinotti, Julinda Stefa
Pervasive Mob. Comput.1
2016 Big data analytics as-a-service: Issues and challenges
abstract
Big Data domain is one of the most promising ICT sectors with substantial expectations both on the side of market growing and design shift in the area of data storage managment and analytics. However, today, the level of complexity achieved and the lack of standardisation of Big Data management architectures represent a huge barrier towards the adoption and execution of analytics especially for those organizations and SMEs not including a sufficient amount of competences and knowledge. The full potential of Big Data Analytics (BDA) can be unleashed only through the definition of approaches that accomplish Big Data users' expectations and requirements, also when the latter are fuzzy and ambiguous. Under these premises, we propose Big Data Analytics-as-a-Service (BDAaaS) as the next-generation Big Data Analytics paradigm and we discuss issues and challenges from the BDAaaS design and development perspective.
Claudio A. Ardagna, Paolo Ceravolo, Ernesto Damiani
IEEE BigData1
2016 A Configuration-Independent Score-Based Benchmark for Distributed Databases
abstract
The business potential of big data is leading to a data-driven economy, where low-cost and low-latency data analysis represents a major competitive advantage. The research community has proposed many technological solutions for big data, such as NoSQL databases, which are difficult to evaluate and compare via standard IT procurement procedures. In addition, lack of competences in big data domains make procurement of big data solutions a tedious and uncertain process, which might impair the success of a business. In this paper, we present a score-based benchmark for distributed databases, which supports adopters in selecting a solution that fits their needs. The proposed benchmark is independent from the configurations of the specific database and deployment environment, requires low effort on the part of end users, is extensible and can be applied to both SQL and NoSQL databases, can be used to evaluate databases according to different properties (e.g., performance, consistency), and can be integrated with existing benchmarks to reduce the burden of their execution. We experimentally evaluate our methodology to validate its effectiveness.
Claudio A. Ardagna, Ernesto Damiani, Fulvio Frati, Davide Rebeccani
IEEE Trans. Serv. Comput.1
2015 Toward Security and Performance Certification of Open Stack
abstract
Cloud users and service providers are increasingly concerned about the management of their data and the behavior of the applications they use/own once stored/deployed in the cloud. They therefore ask for enhanced assurance solutions, which partially mitigate the new risks and threats they are facing. Among existing solutions, certification has been widely adopted as a preferable approach to increase trust in the cloud. In this paper, after briefly discussing our test-based certification scheme for the cloud, we show a real certification process aimed to certify Open Stack, an open source IaaS solution for managing infrastructure resources. In particular, we first describe the testing activities executed to certify Open Stack for security and performance properties. We then illustrate the obtained results and the outcomes of the certification process.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Filippo Gaudenzi, Roberto Veca
CLOUD2
2015 IEEE Services Visionary Track on Security and Privacy Engineering (SPE 2015)
abstract
Message from the IEEE Services Visionary Track on Security and Privacy Engineering (SPE 2015) Program Chairs.
Claudio A. Ardagna, Meiko Jensen, Miguel Vargas Martin
SERVICES1
2014 A Competitive Scalability Approach for Cloud Architectures
abstract
The success of cloud computing has radically changed the way in which services are implemented and deployed, and made accessible to external and remote users. The cloud computing paradigm, in fact, supports a vision of distributed IT where software services and applications are outsourced and used on a pay-as-you-go basis. In this context, the ability to guarantee an effective management of cloud performance and to support automatic scalability become fundamental requirements. Cloud users are increasingly interested in a transparent and coherent vision of cloud, where performance is guaranteed in different scenarios, and under different and heterogeneous loads. In this paper, we analyze the benefits of an integrated scalability approach at different layers of the cloud stack, focusing on the computing infrastructure and database layers. To this aim, we provide different performance metrics and a set of rules based on them to evaluate the status of the cloud stack and scale it on demand to maintain stable performance. We then implement a proof-of-concept architecture to experimentally analyze cloud performance in three scenarios of scalability: computing infrastructure only, database only, and the case in which computing infrastructure and database compete for resources.
Claudio A. Ardagna, Ernesto Damiani, Fulvio Frati, Guido Montalbano, Davide Rebeccani, Marco Ughetti
IEEE CLOUD1
2014 4th IEEE 2014 Services Workshop on Security and Privacy Engineering - Message from the SPE 2014 Workshop Chairs
abstract
Welcome to the 4th IEEE 2014 Services Workshop on Security and Privacy Engineering (SPE 2014), June 28, 2014, Anchorage, Alaska, USA. SPE 2014 is co-located with IEEE 10th World Congress on Services (IEEE SERVICES 2014).
Claudio A. Ardagna, Meiko Jensen, Zhixiong Chen 0005, Ernesto Damiani
SERVICES1
2014 An Anonymous End-to-End Communication Protocol for Mobile Cloud Environments
abstract
The increasing spread of mobile cloud computing paradigm is changing the traditional mobile communication infrastructure. Today, smartphones can rely on virtual (software) “clones” in the cloud, offering backup/recovery solutions as well as the possibility to offload computations. As a result, clones increase the communication and computation capabilities of smartphones, making their limited batteries last longer. Unfortunately, mobile cloud introduces new privacy risks, since personal information of the communicating users is distributed among several parties (e.g., cellular network operator, cloud provider). In this paper, we propose a solution implementing an end-to-end anonymous communication protocol between two users in the network, which leverages properties of social networks and ad hoc wireless networks. We consider an adversary model where each party observing a portion of the communication possibly colludes with others to uncover the identity of communicating users. We then extensively analyze the security of our protocol and the anonymity preserved against the above adversaries. Most importantly, we assess the performance of our solution by comparing it to Tor on a real testbed of 36 smartphones and relative clones running on Amazon EC2 platform.
Claudio A. Ardagna, Mauro Conti, Mario Leone, Julinda Stefa
IEEE Trans. Serv. Comput.1
2013 Preserving Smartphone Users' Anonymity in Cloudy Days
abstract
The mobile cloud computing paradigm involves communications between smartphones and their virtual (software) clones in the cloud. It offers both backup/recovery solutions as well as offload of mobile computations, increasing the communication and computation capabilities of smartphones and making their limited batteries last longer. Unfortunately, in this scenario, the privacy of the users is at stake. The cellular network operator knows how often users contact the cloud, and the cloud provider knows how often users' clones contact each other. We address this privacy problem by providing an anonymous communication protocol, leveraging properties of social networks and ad-hoc wireless networks. Our solution provides anonymous end-to-end communication between two users in the network, and in turn between a user and her clone in the cloud. The proposal copes with an adversary model, where each party observing a portion of the communication (including the cloud provider and the cellular network operator) possibly colludes with others to uncover the identity of communicating users.
Claudio A. Ardagna, Mauro Conti, Mario Leone, Julinda Stefa
ICCCN1
2013 Security Certification of Composite Services: A Test-Based Approach
abstract
Accurate and lightweight evaluation of web service security properties is a key problem, especially when business processes are dynamically built by composing atomic services provided by different suppliers at runtime. In this paper, we tackle this problem by proposing a security certification approach that virtually certifies a composite service for a set of security properties, starting from certificates awarded to the component services.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani
ICWS2
2013 Providing Users' Anonymity in Mobile Hybrid Networks
abstract
We present a novel hybrid communication protocol that guarantees mobile users’ anonymity against a wide-range of adversaries by exploiting the capability of handheld devices to connect to both WiFi and cellular networks. Unlike existing anonymity schemes, we consider all parties that can intercept communications between a mobile user and a server as potential privacy threats. We formally quantify the privacy exposure and the protection of our system in the presence of malicious neighboring peers, global WiFi eavesdroppers, and omniscient mobile network operators, which possibly collude to breach user’s anonymity or disrupt the communication. We also describe how a micropayment scheme that suits our mobile scenario can provide incentives for peers to collaborate in the protocol. Finally, we evaluate the network overhead and attack resiliency of our protocol using a prototype implementation deployed in Emulab and Orbit, and our probabilistic model.
Claudio A. Ardagna, Sushil Jajodia, Pierangela Samarati, Angelos Stavrou
ACM Trans. Internet Techn.1
2013 A test-based security certification scheme for web services
abstract
The Service-Oriented Architecture (SOA) paradigm is giving rise to a new generation of applications built by dynamically composing loosely coupled autonomous services. Clients (i.e., software agents acting on behalf of human users or service providers) implementing such complex applications typically search and integrate services on the basis of their functional requirements and of their trust in the service suppliers. A major issue in this scenario relates to the definition of an assurance technique allowing clients to select services on the basis of their nonfunctional requirements and increasing their confidence that the selected services will satisfy such requirements. In this article, we first present an assurance solution that focuses on security and supports a test-based security certification scheme for Web services. The certification scheme is driven by the security properties to be certified and relies upon a formal definition of the service model. The evidence supporting a certified property is computed using a model-based testing approach that, starting from the service model, automatically generates the test cases to be used in the service certification. We also define a set of indexes and metrics that evaluate the assurance level and the quality of the certification process. Finally, we present our evaluation toolkit and experimental results obtained applying our certification solution to a financial service implementing the Interactive Financial eXchange (IFX) standard.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani, Francesco Saonara
ACM Trans. Web2
2012 Scalability Patterns for Platform-as-a-Service
abstract
Platform-as-a-Service is a cloud-based approach that provides enterprises with all the functionalities for developing, deploying, and administering services, without the burden of installing, configuring, and managing the underlying middleware, operating system, and hardware. In this context, scalability becomes a fundamental requirement, and appropriate solutions need to be studied and evaluated. In this paper, we present different scalability patterns for a Platform-as-a-Service infrastructure and a two-level approach to performance monitoring allowing automatic scalability management. We also provide a performance evaluation of the scalability patterns on a Service-Oriented Architecture (SOA) PaaS, which considers the impact on performance of SOA security standards.
Claudio A. Ardagna, Ernesto Damiani, Fulvio Frati, Davide Rebeccani, Marco Ughetti
IEEE CLOUD1
2012 A Low-Cost Security Certification Scheme for Evolving Services
abstract
Security certification schemes for Service-Oriented Architecture (SOA) extend service specifications with the evidence that a service supports a set of security properties and provides a given level of assurance. However, services are subject to continuous refinements, and uncontrolled changes can easily invalidate existing certification results and require re-certification from scratch, with high costs and overheads on service providers. In this paper, we present an approach to manage the impact of service evolution on security certification. Our approach aims to support the incremental certification of evolving services and re-use, as much as possible, the certification evidence available from older certificates in the release of a new certificate.
Marco Anisetti, Claudio A. Ardagna, Ernesto Damiani
ICWS2
2012 Landmark-assisted location and tracking in outdoor mobile network
Marco Anisetti, Claudio A. Ardagna, Valerio Bellandi, Ernesto Damiani, Mario Döller, Florian Stegmaier, Tilmann Rabl, Harald Kosch, Lionel Brunie
Multim. Tools Appl.2
2011 Editorial
Ernesto Damiani, Sigrid Gürgens, Antonio Maña, George Spanoudakis, Claudio A. Ardagna
J. Syst. Archit.5
2011 An Obfuscation-Based Approach for Protecting Location Privacy
abstract
The pervasive diffusion of mobile communication devices and the technical improvements of location techniques are fostering the development of new applications that use the physical position of users to offer location-based services for business, social, or informational purposes. In such a context, privacy concerns are increasing and call for sophisticated solutions able to guarantee different levels of location privacy to the users. In this paper, we address this problem and present a solution based on different obfuscation operators that, when used individually or in combination, protect the privacy of the location information of users. We also introduce an adversary model and provide an analysis of the proposed obfuscation operators to evaluate their robustness against adversaries aiming to reverse the obfuscation effects to retrieve a location that better approximates the location of the users. Finally, we present some experimental results that validate our solution.
Claudio A. Ardagna, Marco Cremonini, Sabrina De Capitani di Vimercati, Pierangela Samarati
IEEE Trans. Dependable Secur. Comput.1
2011 Expressive and Deployable Access Control in Open Web Service Applications
abstract
Traditional access control solutions, based on preliminary identification and authentication of the access requester, are not adequate for the context of open web service systems, where servers generally do not have prior knowledge of the requesters. The research community has acknowledged such a paradigm shift and several investigations have been carried out for new approaches to regulate access control in open dynamic settings. Typically based on logic, such approaches, while appealing for their expressiveness, result not applicable in practice, where simplicity, efficiency, and consistency with consolidated technology are crucial. The eXtensible Access Control Markup Language (XACML) has established itself as the emerging technological solution for controlling access in an interoperable and flexible way. Although supporting the most common policy representation mechanisms and having acquired a significant spread in the research community and the industry, XACML still suffers from some limitations which impact its ability to support actual requirements of open web-based systems. In this paper, we provide a simple and effective formalization of novel concepts that have to be supported for enforcing the new access control paradigm needed in open scenarios, toward the aim of providing an expressive solution actually deployable with today's technology. We illustrate how the concepts of our model can be deployed in the XACML standard by exploiting its extension points for the definition of new functions, and introducing a dialog management framework to enable access control interactions between web service clients and servers.
Claudio A. Ardagna, Sabrina De Capitani di Vimercati, Stefano Paraboschi, Eros Pedrini, Pierangela Samarati, Mario Verdicchio
IEEE Trans. Serv. Comput.1
2011 Map-Based Location and Tracking in Multipath Outdoor Mobile Networks
abstract
Technical enhancements of mobile technologies are paving the way to the definition of high-quality and accurate geolocation solutions based on data collected and managed by GSM/3G networks. We present a technique that provides geolocation and mobility prediction both at network and service level, does not require any change to the existing mobile network infrastructure, and is entirely performed on the mobile network side, making it more robust than other positioning systems with respect to location spoofing and other terminal-based security threats. Our approach is based on a novel database correlation technique over Received Signal Strength Indication (RSSI) data, and provides a geolocation and tracking technique based on advanced map- and mobility-based filtering. The performance of the geolocation algorithm has been carefully validated by an extensive experimentation, carried out on real data collected from the mobile network antennas of a complex urban environment.
Marco Anisetti, Claudio A. Ardagna, Valerio Bellandi, Ernesto Damiani, Salvatore Reale
IEEE Trans. Wirel. Commun.2
2010 Providing Mobile Users' Anonymity in Hybrid Networks
Claudio A. Ardagna, Sushil Jajodia, Pierangela Samarati, Angelos Stavrou
ESORICS1
2010 Fine-Grained Disclosure of Access Policies
Claudio A. Ardagna, Sabrina De Capitani di Vimercati, Sara Foresti, Gregory Neven, Stefano Paraboschi, Franz-Stefan Preiss, Pierangela Samarati, Mario Verdicchio
ICICS1
2010 Access control for smarter healthcare using policy spaces
Claudio A. Ardagna, Sabrina De Capitani di Vimercati, Sara Foresti, Tyrone Grandison, Sushil Jajodia, Pierangela Samarati
Comput. Secur.1
2010 Exploiting cryptography for privacy-enhanced access control: A result of the PRIME Project
abstract
We conduct more and more of our daily interactions over electronic media. The EC-funded project PRIME (Privacy and Identity Management for Europe) envisions that individuals will be able to interact in this information society in a secure and safe way while retaining control of their privacy. The p roject had set out to prove that existing privacy-enhancing technologies allow for the construction of a user-controlled identity management system that comes surprisingly close to this vision. This paper describes two key elements of the PRIME identity management systems: anonymous credentials and policy languages that fully exploit the advanced functionality offered by anonymous credentials. These two key elements enable the users to carry out transactions, e.g., over the Internet, revealing only the strictly necessary personal information. Apart from presenting for the first time these two key results, this paper also motivates the need for privacy enhancing identity management, gives concrete requirements for such a system and then describes the key principles of the PRIME identity management solution.
Claudio A. Ardagna, Jan Camenisch, Markulf Kohlweiss, Ronald E. Leenes, Gregory Neven, Bart Priem, Pierangela Samarati, Dieter Sommer, Mario Verdicchio
J. Comput. Secur.1
2009 Landscape-aware location-privacy protection in location-based services
Claudio A. Ardagna, Marco Cremonini, Gabriele Gianini
J. Syst. Archit.1
2008 Regulating Exceptions in Healthcare Using Policy Spaces
Claudio A. Ardagna, Sabrina De Capitani di Vimercati, Tyrone Grandison, Sushil Jajodia, Pierangela Samarati
DBSec1
2008 A privacy-aware access control system
abstract
The protection of privacy is an increasing concern in our networked society because of the growing amount of personal information that is being collected by a number of commercial and public services. Emerging scenarios of user–service interactions i
Claudio A. Ardagna, Marco Cremonini, Sabrina De Capitani di Vimercati, Pierangela Samarati
J. Comput. Secur.1
2007 Anomalies Detection in Mobile Network Management Data
Marco Anisetti, Claudio A. Ardagna, Valerio Bellandi, Elisa Bernardoni, Ernesto Damiani, Salvatore Reale
DASFAA2
2007 Location Privacy Protection Through Obfuscation-Based Techniques
Claudio A. Ardagna, Marco Cremonini, Ernesto Damiani, Sabrina De Capitani di Vimercati, Pierangela Samarati
DBSec1
2007 A Middleware Architecture for Integrating Privacy Preferences and Location Accuracy
Claudio A. Ardagna, Marco Cremonini, Ernesto Damiani, Sabrina De Capitani di Vimercati, Pierangela Samarati
SEC1
2006 Supporting location-based conditions in access control policies
abstract
Location-based Access Control (LBAC) techniques allow taking users' physical location into account when determining their access privileges. In this paper, we present an approach to LBAC aimed at integrating location-based conditions along with a generic access control model, so that a requestor can be granted or denied access by checking her location as well as her credentials. Our LBAC model includes a novel way of taking into account the limitations of the technology used to ascertain the location of the requester. Namely, we describe how location verification can be encapsulated as a service, representing location technologies underlying it in terms of two semantically uniform service level agreement (SLA) parameters called confidence and timeout. Based on these parameters, we present the formal definition of a number of location-based predicates, their management, evaluation, and enforcement. The challenges that such an extension to traditional access control policies inevitably carries are discussed also with reference to detailed examples of LBAC policies.
Claudio A. Ardagna, Marco Cremonini, Ernesto Damiani, Sabrina De Capitani di Vimercati, Pierangela Samarati
AsiaCCS1
2006 Enhancing User Privacy Through Data Handling Policies
Claudio A. Ardagna, Sabrina De Capitani di Vimercati, Pierangela Samarati
DBSec1
2006 CAS++: An Open Source Single Sign-On Solution for Secure e-Services
Claudio A. Ardagna, Ernesto Damiani, Sabrina De Capitani di Vimercati, Fulvio Frati, Pierangela Samarati
SEC1
2005 Towards Privacy-Enhanced Authorization Policies and Languages
Claudio A. Ardagna, Ernesto Damiani, Sabrina De Capitani di Vimercati, Pierangela Samarati
DBSec1
2005 Offline Expansion of XACML Policies Based on P3P Metadata
Claudio A. Ardagna, Ernesto Damiani, Sabrina De Capitani di Vimercati, Cristiano Fugazza, Pierangela Samarati
ICWE1
2004 XML-based access control languages
Claudio A. Ardagna, Ernesto Damiani, Sabrina De Capitani di Vimercati, Pierangela Samarati
Inf. Secur. Tech. Rep.1