EDBT 2026 Demo / reviewers in the wild / expert
Mirco Marchetti
dblp:65/4513
· DBLP profile ↗
49ranked-venue papers
4as first author
19since 2021 · last 2025
0000-0002-7408-6906ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 2 since 2021Computer networks · 8 · 1 first-authorSystems, architecture and hardware · 4 · 1 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial AttacksabstractGraph Neural Networks (GNNs) represent a promising solution for Machine Learning (ML) based Network Intrusion Detection Systems (NIDS), thanks to their ability to leverage both network flow features and topological patterns. While GNN classifiers demonstrate superior robustness against feature-based adversarial attacks compared to other ML detectors, they remain vulnerable to structural adversarial attacks, where an attacker perturbs the underlying network graph topology by injecting edges or inserting nodes. Such attacks pose a realistic and severe threat, undermining the reliability of GNN-based NIDS in practical deployments. While countermeasures have been proposed in the literature, they often rely on assumptions that are unrealistic in real-world cybersecurity scenarios. In this paper, we propose a defense framework based on adversarial training to strengthen GNN-based NIDS against structural attacks. We generate adversarial samples by strategically replacing the source and destination nodes in benign network flows, thereby efficiently mimicking edge injection attacks. We evaluate our approach on two widely used datasets (CTU-13 and TON-IoT) using EGraphSAGE as the base GNN classifier. Experimental results show that our approach produces hardened detectors with superior detection performance on clean graphs and enhanced robustness against structural adversarial attacks. Dimitri Galli, Andrea Venturi, Dario Stabili, Mauro Andreolini, Mirco Marchetti |
NCA | 5 |
| 2025 | Network-efficient authenticated pseudonym-based V2X communications with constant revocation costsabstractStandard Vehicle-to-everything (V2X) communications guarantee privacy against tracking by provisioning each vehicle with many conditionally unlinkable pseudonym certificates, which can be linked to each other only with knowledge of a secret information, disclosed by ad-hoc authorities in case of misbehavior for efficient revocation. Certificates are bound to independent keys, but include pseudo-random indexing values which enable such an efficient mechanism at the expense of increasing network overhead of all V2X messages. We propose a novel network-efficient protocol where each vehicle is provisioned with conditionally unlinkable pseudo-random asymmetric key pairs, thus removing the need for linkage values and reducing network overhead while still supporting revocation at constant network costs. Our approach represents a novel application of hierarchical deterministic homomorphic key derivation schemes, which are mostly known for deterministic wallets in the context of blockchains. Compared to standards based on explicit certificates, our approach has lower network overhead, no computational overhead for securing communications, and same cryptographic assumptions. Computational costs for key management operations are higher, but still affordable. We analyze the costs of our proposal both asymptotically and analytically when instantiated with the NIST p-256 elliptic curve recommended by standards. Mattia Trabucco, Giovanni Gambigliani Zoccoli, Mirco Marchetti, Luca Ferretti |
NCA | 3 |
| 2025 | That's what you signed for: evaluating user perception about privacy data in infotainment systemsabstractThe growing integration of data-driven technologies in automotive infotainment systems has heightened privacy concerns, yet user awareness remains limited. This study investigates how perceptions of privacy evolve following an intervention designed to raise awareness about data collection practices in these systems. A survey of 932 participants, structured in pre- and post-intervention phases, highlights significant changes in the prioritization of infotainment system features. Through paired statistical analysis and reliability validation, we observe a marked increase in the perceived importance of privacy-related aspects, particularly data precision and collection frequency. Our results underline the potential of targeted interventions to reshape consumer attitudes, emphasizing the need for enhanced transparency in automotive data management practices. Francesco Faenza, Dario Stabili, Luca Ferretti, Mirco Marchetti |
VTC2025-Fall | 4 |
| 2025 | RADAR: a Radio-based Analytics for Dynamic Association and Recognition of pseudonyms in VANETsabstractThis paper presents RADAR, a tracking algorithm for vehicles participating in Cooperative Intelligent Transportation Systems (C-ITS) that exploits multiple radio signals emitted by a modern vehicle to break privacy-preserving pseudonym schemes deployed in VANETs. This study shows that by combining Dedicated Short Range Communication (DSRC) and Wi-Fi probe request messages broadcast by the vehicle, it is possible to improve tracking over standard de-anonymization approaches that only leverage DSRC, especially in realistic scenarios where the attacker does not have full coverage of the entire vehicle path. The experimental evaluation compares three different metrics for pseudonym and Wi-Fi probe identifier association (Count, Statistical RSSI, and Pearson RSSI), demonstrating that the Pearson RSSI metric is better at tracking vehicles under pseudonym-changing schemes in all scenarios and against previous works. As an additional contribution to the state-of-the-art, we publicly release all implementations and simulation scenarios used in this work [1]. Giovanni Gambigliani Zoccoli, Filip Valgimigli, Dario Stabili, Mirco Marchetti |
VTC2025-Fall | 4 |
| 2024 | Cybersecurity Domains: A design pattern for creating Zero Trust Architectures through microsegmentationabstractPerimeter defense strategies are inadequate to ensure cybersecurity of infrastructures consisting of heterogeneous and dynamic resources. The Zero Trust security model emerges as the most promising solution to mitigate risks and protect assets, but significant organizational and implementation challenges hinder its adoption. Microsegmentation of networked systems composed by dynamic IT components and mobile devices cause several technological and management concerns. We present a comprehensive analysis of microsegmentation with the goal of identifying the key aspects that distinguish it from traditional perimeter defenses. We then propose a modular architectural design pattern that ensures adherence to the Zero Trust principles and satisfies its security constraints. This design is based on the concept of Security Domain, which represents the fundamental unit of network segmentation. By combining multiple Security Domains and following precise rules that provably preserve network security, it becomes possible to create complex infrastructures from elementary building blocks. We provide also a formal specification of the proposed design by means of the TLA+ modeling language. We leverage this model to verify its correctness and security properties even in the presence of insider threats. Claudio Zanasi, Mirco Marchetti, Michele Colajanni |
DASC | 2 |
| 2024 | HackCar: a test platform for attacks and defenses on a cost-contained automotive architectureabstractIn this paper, we introduce the design of HackCar, a testing platform for replicating attacks and defenses on a generic automotive system without requiring access to a complete vehicle. This platform empowers security researchers to illustrate the consequences of attacks targeting an automotive system on a realistic platform, facilitating the development and testing of security countermeasures against both existing and novel attacks. The HackCar platform is built upon an F1−10thmodel, to which various automotive-grade microcontrollers are connected through automotive communication protocols. This solution is crafted to be entirely modular, allowing for the creation of diverse test scenarios. Researchers and practitioners can thus develop innovative security solutions while adhering to the constraints of automotive-grade microcontrollers. We showcase our design by comparing it with a real, licensed, and unmodified vehicle. Additionally, we analyze the behavior of the HackCar in both an attack-free scenario and a scenario where an attack on in-vehicle communication is deployed. Dario Stabili, Filip Valgimigli, Edoardo Torrini, Mirco Marchetti |
IV | 4 |
| 2024 | RealCAN: bringing real-time capabilities to canplayerabstractIn this paper we present RealCAN, a real-time capable extension of the canplayer tool available in can-utils, a collection of utilities for interacting with Controller Area Network bus systems on Linux-based operating systems. In particular, RealCAN addresses the main limitation of working with fixed time intervals while replaying previously collected CAN traces with the canplayer tool, allowing developers, engineers and researchers to replay CAN traffic data by maintaining the original time difference between consecutive messages. Performance benchmarks of RealCAN demonstrate its effectiveness in meeting strict timing requirements for critical applications in both simulated environment and real CAN test setups. Giovanni Gambigliani Zoccoli, Dario Stabili, Mirco Marchetti |
VTC Fall | 3 |
| 2024 | Performance Comparison of Timing-Based Anomaly Detectors for Controller Area Network: A Reproducible StudyabstractThis work presents an experimental evaluation of the detection performance of eight different algorithms for anomaly detection on the Controller Area Network (CAN) bus of modern vehicles based on the analysis of the timing or frequency of CAN messages. This work solves the current limitations of related scientific literature, which is based on a private dataset and lacks open implementations and a detailed description of the detection algorithms. These drawbacks prevent the reproducibility of published results, making it impossible to compare a novel proposal against related work, thus hindering the advancement of science. This article solves these issues by publicly releasing implementations and labeled datasets and by describing unbiased experimental comparisons. Francesco Pollicino, Dario Stabili, Mirco Marchetti |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2023 | Decentralized position detection for moving vehiclesabstractModern cars are equipped with sensors that can detect other moving vehicles and obstacles on the road. However, their range is usually limited to line-of-sight and their accuracy is also limited. To provide information beyond the sensor range, each vehicle broadcasts Basic Safety Messages (BSMs) with its position and speed. For road awareness, it would be best if multiple vehicles could confirm the position (redundancy), using their on-board sensors for verification (diversity), and excluding position and speed errors (plausibility). This paper presents a decentralized solution that uses multiple vantage points to provide more trust in moving vehicle position data. It extends broadcast messages with sensor verification and plausibility filtering. It processes a stream of data from nearby vehicles and for short time periods, to achieve the safety benefits without the privacy risks of long-term data retention. The proposal was evaluated with detailed simulations with different levels of traffic and misbehavior. It provides good detection results with only a limited increase in network and computing resources. Francesco Pollicino, Samih Eisa, Pedro M. Rosa, Miguel L. Pardal, Mirco Marchetti |
VTC2023-Spring | 5 |
| 2023 | Are VANETs pseudonyms effective? An experimental evaluation of pseudonym tracking in adversarial scenarioabstractWith the increasing adoption of Vehicular Ad Hoc Networks (VANETs) for the development of Cooperative Intelligent Transportation Systems (C-ITS) many concerns regarding privacy and anonymity in VANETs have been raised by security researchers and practitioners, highlighting the need for effective mechanisms to protect sensitive information exchanged by connected vehicles. One of the first concerns is related to the vehicle’s identifier, a field contained in the messages sent from the vehicle and that can be used to track the vehicle across the infrastructure, with consequent severe implications on the privacy of the driver. Consequently, VANET communications leverage short-lived pseudonyms instead of persistent vehicle’s identifiers, aiming to enhance the privacy of the vehicle. Pseudonym change schemes proposed in the literature are effective in masking the real sender of a given message, but they do not guarantee privacy against attackers that can monitor and correlate multiple messages among themselves. This paper evaluates 5 different pseudonym change mechanisms against a realistic threat model. Our results demonstrate that it is possible for a realistic attacker to reliably track multiple vehicles, with minor differences across different pseudonym change schemes. Giovanni Gambigliani Zoccoli, Dario Stabili, Mirco Marchetti |
VTC Fall | 3 |
| 2023 | A multidisciplinary detection system for cyber attacks on Powertrain Cyber Physical Systems
Dario Stabili, Raffaele Romagnoli, Mirco Marchetti, Bruno Sinopoli, Michele Colajanni |
Future Gener. Comput. Syst. | 3 |
| 2022 | Comparison of Machine Learning-based anomaly detectors for Controller Area NetworkabstractThis paper presents a comparative analysis of different Machine Learning-based detection algorithms designed for Controller Area Network (CAN) communication on three different datasets. This work focuses on addressing the current limitations of related scientific literature, related to the quality of the publicly available datasets and to the lack of public implementations of the detection solutions presented in literature. Since these issues are preventing the reproducibility of published results and their comparison with novel detection solutions, we remark that it is necessary that all security researchers working in this field start to address them properly to advance the current state-of-the-art in CAN intrusion detection systems. This paper strives to solve these issues by presenting a comparison of existing works on publicly available datasets. Andrea Venturi, Dario Stabili, Francesco Pollicino, Emanuele Bianchi, Mirco Marchetti |
NCA | 5 |
| 2022 | Robustness Evaluation of Network Intrusion Detection Systems based on Sequential Machine LearningabstractThe rise of sequential Machine Learning (ML) methods has paved the way for a new generation of Network Intrusion Detection Systems (NIDS) which base their classification on the temporal patterns exhibited by malicious traffic. Previous work presents successful algorithms in this field, but just a few attempts try to assess their robustness in real-world contexts. In this paper, we aim to fill this gap by presenting a novel evaluation methodology. In particular, we propose a new time-based adversarial attack in which we simulate a delay in the malicious communications that changes the arrangement of the samples in the test set. Moreover, we design an innovative evaluation technique simulating a worst-case training scenario in which the last portion of the training set does not include any malicious flow. Through them, we can evaluate how much sequential ML-based NIDS are sensible to modifications that an adaptive attacker might apply at temporal level, and we can verify their robustness to the unpredictable traffic produced by modern networks. Our experimental campaign validates our proposal against a recent NIDS trained on a public dataset for botnet detection. The results demonstrate its high resistance to temporal adversarial attacks, but also a drastic performance drop when even just 1% of benign flows are injected at the end of the training set. Our findings raise questions about the reliable deployment of sequential ML-NIDS in practice, and at the same time can guide researchers to develop more robust defensive tools in the future. Andrea Venturi, Claudio Zanasi, Mirco Marchetti, Michele Colajanni |
NCA | 3 |
| 2022 | SixPack v2: enhancing SixPack to avoid last generation misbehavior detectors in VANETsabstractThis paper proposes SixPack v2, an enhanced version of the SixPack attack that allows to evade even state-of-the-art misbehavior detection systems. As the original SixPack, SixPack v2 is a dynamic attack targeting other C-ITS entities by simulating the sudden activation of the braking system with consequent activation of the Anti-lock Braking System. SixPack v2 achieves better evasion by improving the main phases of the attack (FakeBrake, Recovery, and Rejoin) through a novel path-reconstruction algorithm that generates a more realistic representation of the real vehicle trajectory. We experimentally evaluate the evasion capabilities of SixPack v2 using the F2MD framework on the LuSTMini city scenario, and we compared the detection performance of the F2MD framework on both versions of SixPack. Results show that SixPack v2 evades detection with a significantly higher likelihood with respect to the initial version of the attack, even against the latest version of F2MD. Gabriele Gambigliani Zoccoli, Francesco Pollicino, Dario Stabili, Mirco Marchetti |
NCA | 4 |
| 2022 | On the effectiveness of BSM communications in V2V emergency scenariosabstractCooperative Intelligent Transportation Systems (CITS) improve driving experience and safety through secure Vehicular Ad-hoc NETworks (VANETs) that satisfy strict security and performance constraints. The use of Vehicle-to-Vehicle (V2V) communications to improve safety in emergency scenarios is already considered in the relevant standards. However, there is a lack of scientific efforts to evaluate and compare the effectiveness of these solutions. This paper improves the state of the art by providing an assessment of the effectiveness of V2V communications in reducing the travel time and safety–relevant events of emergency vehicles. The assessment is based on realistic simulation taking into account real road networks, traffic intensity, and all constraints of V2V communications. Francesco Pollicino, Dario Stabili, Mirco Marchetti |
VTC Spring | 3 |
| 2021 | Accountable and privacy-aware flexible car sharing and rental servicesabstractThe transportation sector is undergoing rapid changes to reduce pollution and increase life quality in urban areas. One of the most effective approaches is flexible car rental and sharing to reduce traffic congestion and parking space issues. In this paper, we envision a flexible car sharing framework where vehicle owners want to make their vehicles available for flexible rental to other users. The owners delegate the management of their vehicles to intermediate services under certain policies, such as municipalities or authorized services, which manage the due infrastructure and services that can be accessed by users. We investigate the design of an accountable solution that allow vehicles owners, who want to share their vehicles securely under certain usage policies, to control that delegated services and users comply with the policies. While monitoring users behavior, our approach also takes care of users privacy, preventing tracking or profiling procedures by other parties. Existing approaches put high trust assumptions on users and third parties, do not consider users' privacy requirements, or have limitations in terms of flexibility or applicability. We propose an accountable protocol that extends standard delegated authorizations and integrate it with Security Credential Management Systems (SCMS), while considering the requirements and constraints of vehicular networks. We show that the proposed approach represents a practical approach to guarantee accountability in realistic scenarios with acceptable overhead. Francesco Pollicino, Luca Ferretti, Dario Stabili, Mirco Marchetti |
NCA | 4 |
| 2021 | Analysis, prevention and detection of ransomware attacks on Industrial Control SystemsabstractWith the advent of Industry 4.0, Industrial Control Systems (ICS) are becoming a prime target for many cyber criminals. We are witnessing a steady increase in the number of ransomware attacks specifically designed to compromise in-dustrial control systems. The consequences of these attacks can be devastating, as they are able to block production processes for days, resulting in a loss of revenue, violation of contractual terms, reputational damage, and sanctions in regulated markets. This paper analyzes two relevant cases of ICS ransomware and proposes a novel solution that is able to detect these infections and stop them before the actual compromise of the systems that control industrial machines and production plants. Experimental evaluation demonstrates the effectiveness of our approach against real malware samples in simulated, realistic ICS environments. Giorgio Valenziano Santangelo, Vincenzo Giuseppe Colacino, Mirco Marchetti |
NCA | 3 |
| 2021 | SixPack: Abusing ABS to avoid Misbehavior detection in VANETsabstractThis paper presents SixPack, a cyber attack to VANET communications that is able to go undetected by the current state-of-the-art anomaly detectors. The SixPack attack is a dynamic attack conducted by an insider attacker who modifies the content of the Basic Safety Messages to pretend a sudden activation of the braking system with the consequent activation of the Anti-lock Braking System, and create a fake representation of the vehicle. The attacker then rejoins the fake representation of the vehicle with the real one, avoiding the current state-of-the-art anomaly detectors. We experimentally evaluated the evasion capabilities of the SixPack attack using the F2MD test framework on the LuST and LuSTMini city scenarios, demonstrating the ability of the attacker to generate a high percentage of false positives that prevent the attack from being detected consistently. Francesco Pollicino, Dario Stabili, Giampaolo Bella, Mirco Marchetti |
VTC Spring | 4 |
| 2021 | Glyph: Efficient ML-Based Detection of Heap Spraying AttacksabstractHeap spraying is probably the most simple and effective memory corruption attack, which fills the memory with malicious payloads and then jumps at a random location in hopes of starting the attacker's routines. To counter this threat, GRAFFITI has been recently proposed as the first OS-agnostic framework for monitoring memory allocations of arbitrary applications at runtime; however, the main contributions of GRAFFITI are on the monitoring system, and its detection engine only considers simple heuristics which are tailored to certain attack vectors and are easily evaded. In this article, we aim to overcome this limitation and propose GLYPH as the first ML-based heap spraying detection system, which is designed to be effective, efficient, and resilient to evasive attackers. GLYPH relies on the information monitored by GRAFFITI, and we investigate the effectiveness of different feature spaces based on information entropy and memory n-grams, and discuss the several engineering challenges we have faced to make GLYPH efficient with an overhead compatible with that of GRAFFITI. To evaluate GLYPH, we build a representative dataset with several variants of heap spraying attacks, and assess GLYPH's resilience against evasive attackers through selective hold-out experiments. Results show that GLYPH achieves high accuracy in detecting spraying and is able to generalize well, outperforming the state-of-the-art approach for heap spraying detection, NOZZLE. Finally, we thoroughly discuss the trade-offs between detection performance and runtime overhead of GLYPH's different configurations. Fabio Pierazzi, Stefano Cristalli, Danilo Bruschi, Michele Colajanni, Mirco Marchetti, Andrea Lanzi |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | An experimental analysis of ECQV implicit certificates performance in VANETsabstractEmerging Cooperative Intelligent Transportation Systems (C-ITS) enable improved driving experience and safety guarantees, but require secure Vehicular Ad-hoc NETworks (VANETs) that must comply to strict performance constraints. Specialized standards have been defined to these aims, such as the IEEE 1609.2 that uses network-efficient cryptographic protocols to reduce communication latencies. The reduced latencies are achieved through a combination of the Elliptic Curve Qu-Vantstone (ECQV) implicit certificate scheme and the Elliptic Curve Digital Signature Algorithm (ECDSA), to guarantee data integrity and authenticity. However, literature lacks implementations and evaluations for vehicular systems. In this paper, we consider the IEEE 1609.2 standard for secure VANETs and investigate the feasibility of ECQV and ECDSA schemes when deployed in C-ITSs. We propose a prototype implementation of the standard ECQV scheme to evaluate its performance on automotive-grade hardware. To the best of our knowledge, this is the first open implementation of the scheme for constrained devices that are characterized by low computational power and low memory. We evaluate its performance against C-ITS communication latency constraints and show that, although even highly constrained devices can support the standard, complying with stricter requirements demands for higher computational resources. Francesco Pollicino, Dario Stabili, Luca Ferretti, Mirco Marchetti |
VTC Fall | 4 |
| 2020 | A Framework for the Evaluation of Trainee Performance in Cyber Range Exercises
Mauro Andreolini, Vincenzo Giuseppe Colacino, Michele Colajanni, Mirco Marchetti |
Mob. Networks Appl. | 4 |
| 2020 | Deep Reinforcement Adversarial Learning Against Botnet Evasion AttacksabstractAs cybersecurity detectors increasingly rely on machine learning mechanisms, attacks to these defenses escalate as well. Supervised classifiers are prone to adversarial evasion, and existing countermeasures suffer from many limitations. Most solutions degrade performance in the absence of adversarial perturbations; they are unable to face novel attack variants; they are applicable only to specific machine learning algorithms. We propose the first framework that can protect botnet detectors from adversarial attacks through deep reinforcement learning mechanisms. It automatically generates realistic attack samples that can evade detection, and it uses these samples to produce an augmented training set for producing hardened detectors. In such a way, we obtain more resilient detectors that can work even against unforeseen evasion attacks with the great merit of not penalizing their performance in the absence of specific attacks. We validate our proposal through an extensive experimental campaign that considers multiple machine learning algorithms and public datasets. The results highlight the improvements of the proposed solution over the state-of-the-art. Our method paves the way to novel and more robust cybersecurity detectors based on machine learning applied to network traffic analytics. Giovanni Apruzzese, Mauro Andreolini, Mirco Marchetti, Andrea Venturi, Michele Colajanni |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2019 | Evaluating the effectiveness of Adversarial Attacks against Botnet DetectorsabstractClassifiers based on Machine Learning are vulnerable to adversarial attacks, which involve the creation of malicious samples that are not classified correctly. While this phenomenon has been extensively studied within the image processing domain, comprehensive analyses are scarce in the cybersecurity field. This is a critical problem because cyber-detectors are being increasingly integrated with machine learning methods, making them suitable targets for skilled attackers leveraging adversarial samples to evade detection. In this paper, we propose a thorough analysis of realistic adversarial attacks performed against network intrusion detection systems that focus on identifying botnet traffic through machine learning classifiers. Our large campaign of experiments involves the most recent public datasets, representing multiple realistic network scenarios. Moreover, we evaluate the impact of these attacks against state-of-the-art detectors relying on different machine learning algorithms, providing a clear overview of this problem. The results outline the fragility of these methods. Our study represent a stepping stone for devising suitable countermeasures to the menace of adversarial attacks against cyber-detectors. Giovanni Apruzzese, Michele Colajanni, Mirco Marchetti |
NCA | 3 |
| 2019 | Detection of Missing CAN Messages through Inter-Arrival Time AnalysisabstractRecent cyber-attacks to real vehicles demonstrated the risks related to connected vehicles, and spawned several research effort aimed at proposing algorithms and architectural solutions to improve the security of these vehicles. Most of the documented attacks to the connected vehicles require the injection of maliciously forged messages to subvert the normal behaviour of the electronic microcontrollers. More recently, researchers discovered that by abusing error isolation mechanisms of the Controller Area Network (CAN), one of the protocols deployed for in-vehicle networking, it is possible to isolate a microcontroller from the vehicle internal network (namely bus-off attack), with possible severe implication on both safety and security. This vulnerability has already been exploited for gaining remote control of a vehicle, by driving a targeted microcontroller in bus-off and impersonating it through the injection of malicious messages on the CAN bus. This paper strives to counter bus-off attacks by proposing an algorithm for the detection of missing messages from the in- vehicle CAN bus. Bus-off attacks to in-vehicle network are simulated by removing messages from valid CAN traces recorded from an unmodified licensed vehicle. Experimental evaluations of our proposal and comparisons with previous work demonstrate that the proposed algorithms outperforms other detection algorithms, achieving almost perfect detection (F-score equal or near to 1.0) across different tests. Dario Stabili, Mirco Marchetti |
VTC Fall | 2 |
| 2019 | READ: Reverse Engineering of Automotive Data FramesabstractSecurity analytics and forensics applied to in-vehicle networks are growing research areas that gained relevance after recent reports of cyber-attacks against unmodified licensed vehicles. However, the application of security analytics algorithms and tools to the automotive domain is hindered by the lack of public specifications about proprietary data exchanged over in-vehicle networks. Since the controller area network (CAN) bus is the de-facto standard for the interconnection of automotive electronic control units, the lack of public specifications for CAN messages is a key issue. This paper strives to solve this problem by proposing READ: a novel algorithm for the automatic Reverse Engineering of Automotive Data frames. READ has been designed to analyze traffic traces containing unknown CAN bus messages in order to automatically identify and label different types of signals encoded in the payload of their data frames. Experimental results based on CAN traffic gathered from a licensed unmodified vehicle and validated against its complete formal specifications demonstrate that the proposed algorithm can extract and classify more than twice the signals with respect to the previous related work. Moreover, the execution time of signal extraction and classification is reduced by two orders of magnitude. Applications of READ to CAN messages generated by real vehicles demonstrate its usefulness in the analysis of CAN traffic. Mirco Marchetti, Dario Stabili |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Fog-based Secure Communications for Low-power IoT DevicesabstractDesigning secure, scalable, and resilient IoT networks is a challenging task because of resource-constrained devices and no guarantees of reliable network connectivity. Fog computing improves the resiliency of IoT, but its security model assumes that fog nodes are fully trusted. We relax this latter constraint by proposing a solution that guarantees confidentiality of messages exchanged through semi-honest fog nodes thanks to a lightweight proxy re-encryption scheme. We demonstrate the feasibility of the solution by applying it to IoT networks of low-power devices through experiments on microcontrollers and ARM-based architectures. Luca Ferretti, Mirco Marchetti, Michele Colajanni |
ACM Trans. Internet Techn. | 2 |
| 2018 | Analyses of Secure Automotive Communication Protocols and Their Impact on Vehicles Life-CycleabstractModern vehicles are complex cyber physical systems where communication protocols designed for physically isolated networks are now employed to connect Internet-enabled devices. This unforeseen increase in connectivity creates novel attack surfaces, and exposes safety-critical functions of the vehicle to cyber attacks. As standard security solutions are not applicable to vehicles due to resource constraints and compatibility issues, research is proposing tailored approaches to cope with existing systems and to design next generations vehicles. In this paper we focus on solutions based on cryptographic protocols to protect in-vehicle communications and prevent unauthorized manipulation of the vehicle behaviors. Existing proposals consider vehicles as monolithic systems and evaluate performance and costs of the proposed solutions without considering the complex life-cycle of automotive components and the multifaceted automotive ecosystem that includes a large number of actors. The main contribution of this paper is a study of the impact of security solutions by considering vehicles life-cycle. We model existing proposals and highlight their impacts on vehicles production and maintenance operations by taking into consideration interactions among multiple players. Finally, we give insights on the requirements of architectures for secure intra-vehicular protocols. Dario Stabili, Luca Ferretti, Mirco Marchetti |
SMARTCOMP | 3 |
| 2018 | A symmetric cryptographic scheme for data integrity verification in cloud databases
Luca Ferretti, Mirco Marchetti, Mauro Andreolini, Michele Colajanni |
Inf. Sci. | 2 |
| 2017 | Verifiable Delegated Authorization for User-Centric Architectures and an OAuth2 ImplementationabstractDelegated authorization protocols have become wide-spread to implement Web applications and services, where some popular providers managing people identity information and personal data allow their users to delegate third party Web services to access their data. In this paper, we analyze the risks related to untrusted providers not behaving correctly, and we solve this problem by proposing the first verifiable delegated authorization protocol that allows third party services to verify the correctness of users data returned by the provider. The contribution of the paper is twofold: we show how delegated authorization can be cryptographically enforced through authenticated data structures protocols, we extend the standard OAuth2 protocol by supporting efficient and verifiable delegated authorization including database updates and privileges revocation. Luca Ferretti, Mirco Marchetti, Michele Colajanni |
COMPSAC (2) | 2 |
| 2017 | Anomaly detection of CAN bus messages through analysis of ID sequencesabstractThis paper proposes a novel intrusion detection algorithm that aims to identify malicious CAN messages injected by attackers in the CAN bus of modern vehicles. The proposed algorithm identifies anomalies in the sequence of messages that flow in the CAN bus and is characterized by small memory and computational footprints, that make it applicable to current ECUs. Its detection performance are demonstrated through experiments carried out on real CAN traffic gathered from an unmodified licensed vehicle. Mirco Marchetti, Dario Stabili |
Intelligent Vehicles Symposium | 1 |
| 2017 | Identifying malicious hosts involved in periodic communicationsabstractAfter many research efforts, Network Intrusion Detection Systems still have much room for improvement. This paper proposes a novel method for automatic and timely analysis of traffic generated by large networks, which is able to identify malicious external hosts even if their activities do not raise any alert by existing defensive systems. Our proposal focuses on periodic communications, since our experimental evaluation shows that they are more related to malicious activities, and it can be easily integrated with other detection systems. We highlight that periodic network activities can occur at very different intervals ranging from seconds to hours, hence a timely analysis of long time-windows of the traffic generated by large organizations is a challenging task in itself. Existing work is primarily focused on identifying botnets, whereas the method proposed in this paper has a broader target and aims to detect external hosts that are likely involved in any malicious operation. Since malware-related network activities can be considered as rare events in the overall traffic, the output of the proposed method is a manageable graylist of external hosts that are characterized by a considerably higher likelihood of being malicious compared to the entire set of external hosts contacted by the monitored large network. A thorough evaluation on a real large network traffic demonstrates the effectiveness of our proposal, which is capable of automatically selecting only dozens of suspicious hosts from hundreds of thousands, thus allowing security operators to focus their analyses on few likely malicious targets. Giovanni Apruzzese, Mirco Marchetti, Michele Colajanni, Gabriele Gambigliani Zoccoli, Alessandro Guido |
NCA | 2 |
| 2016 | Implementation of Verified Set Operation Protocols Based on Bilinear Accumulators
Luca Ferretti, Michele Colajanni, Mirco Marchetti |
CANS | 3 |
| 2016 | Guaranteeing Correctness of Bulk Operations in Outsourced Databases
Luca Ferretti, Michele Colajanni, Mirco Marchetti |
DBSec | 3 |
| 2016 | Analysis of high volumes of network traffic for Advanced Persistent Threat detection
Mirco Marchetti, Fabio Pierazzi, Michele Colajanni, Alessandro Guido |
Comput. Networks | 1 |
| 2016 | Exploratory security analytics for anomaly detection
Fabio Pierazzi, Sara Casolari, Michele Colajanni, Mirco Marchetti |
Comput. Secur. | 4 |
| 2015 | Enforcing Correct Behavior without Trust in Cloud Key-Value DatabasesabstractTraditional computation outsourcing and modern cloud computing are affected by a common risk of distrust between service requestor and service provider. We propose a novel protocol, named Probus, that offers guarantees of correct behavior to both parts without assuming any trust relationship between them in the context of cloud-based key-value databases. Probus allows a service requestor to have evidence of cloud provider misbehavior on its data, and a cloud provider to defend itself from false accusations by demonstrating the correctness of its operations. Accusation and defense proofs are based on cryptographic mechanisms that can be verified by a third party. Probus improves the state-of-the-art by introducing novel solutions that allow for efficient verification of data security properties and by limiting the overhead required to provide its security guarantees. Thanks to Probus it is possible to check the correctness of all the results generated by a cloud service, thus improving weaker integrity assurance based on probabilistic verifications that are adopted by related work. Andrea Andreoli, Luca Ferretti, Mirco Marchetti, Michele Colajanni |
CSCloud | 3 |
| 2015 | A collaborative framework for intrusion detection in mobile networks
Mauro Andreolini, Michele Colajanni, Mirco Marchetti |
Inf. Sci. | 3 |
| 2014 | Efficient detection of unauthorized data modification in cloud databasesabstractCloud services represent an unprecedented opportunity, but their adoption is hindered by confidentiality and integrity issues related to the risks of outsourcing private data to cloud providers. This paper focuses on integrity and proposes an innovative solution that allows cloud tenants to detect unauthorized modifications to outsourced data while minimizing storage and network overheads. Our approach is based on encrypted Bloom filters, and is designed to allow efficient integrity verification for databases stored in the cloud. We assess the effectiveness of the proposal as well as its performance improvements with respect to existing solutions by evaluating storage and network costs. Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti, Marcello Missiroli |
ISCC | 4 |
| 2014 | Performance and Cost Evaluation of an Adaptive Encryption Architecture for Cloud DatabasesabstractThe cloud database as a service is a novel paradigm that can support several Internet-based applications, but its adoption requires the solution of information confidentiality problems. We propose a novel architecture for adaptive encryption of public cloud databases that offers an interesting alternative to the tradeoff between the required data confidentiality level and the flexibility of the cloud database structures at design time. We demonstrate the feasibility and performance of the proposed solution through a software prototype. Moreover, we propose an original cost model that is oriented to the evaluation of cloud database services in plain and encrypted instances and that takes into account the variability of cloud prices and tenant workloads during a medium-term period. Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti |
IEEE Trans. Cloud Comput. | 4 |
| 2014 | Scalable Architecture for Multi-User Encrypted SQL Operations on Cloud Database ServicesabstractThe success of the cloud database paradigm is strictly related to strong guarantees in terms of service availability, scalability and security, but also of data confidentiality. Any cloud provider assures the security and availability of its platform, while the implementation of scalable solutions to guarantee confidentiality of the information stored in cloud databases is an open problem left to the tenant. Existing solutions address some preliminary issues through SQL operations on encrypted data. We propose the first complete architecture that combines data encryption, key management, authentication and authorization solutions, and that addresses the issues related to typical threat scenarios for cloud database services. Formal models describe the proposed solutions for enforcing access control and for guaranteeing confidentiality of data and metadata. Experimental evaluations based on standard benchmarks and real Internet scenarios show that the proposed architecture satisfies also scalability and performance requirements. Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti |
IEEE Trans. Cloud Comput. | 4 |
| 2014 | Distributed, Concurrent, and Independent Access to Encrypted Cloud DatabasesabstractPlacing critical data in the hands of a cloud provider should come with the guarantee of security and availability for data at rest, in motion, and in use. Several alternatives exist for storage services, while data confidentiality solutions for the database as a service paradigm are still immature. We propose a novel architecture that integrates cloud database services with data confidentiality and the possibility of executing concurrent operations on encrypted data. This is the first solution supporting geographically distributed clients to connect directly to an encrypted cloud database, and to execute concurrent and independent operations including those modifying the database structure. The proposed architecture has the further advantage of eliminating intermediate proxies that limit the elasticity, availability, and scalability properties that are intrinsic in cloud-based solutions. The efficacy of the proposed architecture is evaluated through theoretical analyses and extensive experimental results based on a prototype implementation subject to the TPC-C standard benchmark for different numbers of clients and network latencies. Luca Ferretti, Michele Colajanni, Mirco Marchetti |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | Access Control Enforcement on Query-Aware Encrypted Cloud DatabasesabstractThe diffusion of cloud database services requires a lot of efforts to improve confidentiality of data stored in external infrastructures. We propose a novel scheme that integrates data encryption with users access control mechanisms. It can be used to guarantee confidentiality of data with respect to a public cloud infrastructure, and to minimize the risks of internal data leakage even in the worst case of a legitimate user colluding with some cloud provider personnel. The correctness and feasibility of the proposal is demonstrated through formal models, while the integration in a cloud-based architecture is left to future work. Luca Ferretti, Michele Colajanni, Mirco Marchetti |
CloudCom (2) | 3 |
| 2011 | Defeating NIDS evasion in Mobile IPv6 networksabstractThe diffusion of mobile devices and technologies supporting transparent network mobility can have detrimental effects on network security. We describe how an attacker can lever-age mobility in IPv6 networks to perpetrate known attacks while evading detection by state-of-the-art Network Intrusion Detection Systems (NIDSs). We then propose a new defense strategy based on the exchange of state information among distributed NIDSs. We demonstrate the effectiveness of the proposed solution through a prototype implementation, evaluated experimentally in a Mobile IPv6 network. Michele Colajanni, Luca Dal Zotto, Mirco Marchetti, Michele Messori |
WOWMOM | 3 |
| 2009 | Peer-to-Peer Architecture for Collaborative Intrusion and Malware Detection on a Large Scale
Mirco Marchetti, Michele Messori, Michele Colajanni |
ISC | 1 |
| 2009 | Making Byzantine Fault Tolerant Systems Tolerate Byzantine Faults
Allen Clement, Edmund L. Wong, Lorenzo Alvisi, Michael Dahlin, Mirco Marchetti |
NSDI | 5 |
| 2008 | FlightPath: Obedience vs. Choice in Cooperative Services
Harry C. Li, Allen Clement, Mirco Marchetti, Manos Kapritsos, Luke Robison, Lorenzo Alvisi, Michael Dahlin |
OSDI | 3 |
| 2008 | Collaborative architecture for malware detection and analysis
Michele Colajanni, Daniele Gozzi, Mirco Marchetti |
SEC | 3 |
| 2007 | Enhancing interoperability and stateful analysis of cooperative network intrusion detection systemsabstractA traditional Network Intrusion Detection System (NIDS) is based on a centralized architecture that does not satisfy the needs of most modern network infrastructures characterized by high traffic volumes and complex topologies. The of decentralized NIDS based on multiple sensors is that each of them gets just a partial view of the network traffic and this prevents a stateful and fully reliable traffic analysis. We propose a novel cooperation mechanism that the previous issues through an innovative state management and state migration framework. It allows multiple decentralized sensors to share their internal state, thus accomplishing innovative and powerful traffic analysis. The advanced functionalities and performance of the proposed cooperative framework for network intrusion detection systems are demonstrated through a fully operative prototype. Michele Colajanni, Daniele Gozzi, Mirco Marchetti |
ANCS | 3 |
| 2007 | Dynamic load balancing for network intrusion detection systems based on distributed architecturesabstractIncreasing traffic and the necessity of stateful analyses impose strong computational requirements on network intrusion detection systems (NIDS), and motivate the need of distributed architectures with multiple sensors. In a context of high traffic with heavy tailed characteristics, static rules for dispatching traffic slices among distributed sensors cause severe imbalance. Hence, the distributed NIDS architecture must be combined with adequate mechanisms for dynamic load redistribution. In this paper, we propose and compare different policies for the activation/deactivation of the dynamic load balancer. In particular, we consider and compare single vs. double threshold schemes, and load representations based on resource measures vs. load aggregation models. Our experimental results show that the best combination of a double threshold scheme with a linear aggregation of resource measures is able to achieve a really satisfactory balance of the sensor loads together with a sensible reduction of the number of load balancer activations. Mauro Andreolini, Sara Casolari, Michele Colajanni, Mirco Marchetti |
NCA | 4 |