Manuel Cheminod

dblp:75/6065 · DBLP profile ↗
← Back
18ranked-venue papers
12as first author
8since 2021 · last 2025
0000-0001-5716-7870ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 10 · 4 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 6 first-author · 2 since 2021Security and privacy · 3 · 3 first-author
YearPublicationVenuePosition
2025 A Smart Redundant Version of the MQTT Protocol
abstract
Resilient systems are crucial for modern interconnected applications, especially those with autonomous machine-to-machine communication. Standard network protocols can exhibit unacceptable recovery times for time-critical operations, and systems must withstand various disruptions beyond just connection failures.This paper addresses these vulnerabilities by proposing a robust communication architecture based on an adapted MQTT protocol employing duplicated packet transmission over parallel pathways. The approach, based on redundancy, employs a smart algorithm for selecting the best communication path to rely on. This strategy aims to ensure reliable data delivery and mitigate service interruptions, particularly for demanding industrial applications, while limiting resources and bandwidth consumption. The effectiveness of this architecture is validated through a real testbed implementation and online testing.
Claudio Zunino, Manuel Cheminod, Gianluca Cena, Stefano Vitturi, Alberto Morato, Elena Ferrari 0002, Federico Tramarin
ETFA2
2024 IEEE 1588 (PTP) Over mmWave 5G NR: Preliminary Assessment of the Synchronization Accuracy for TSN Applications
abstract
The extension of Time Sensitive Networking (TSN) to wireless domains is a key enabler for the realization of Industry 4.0 and 5.0 applications. Thanks to their characteristics in terms of latency and bandwidth, and the seamless integration with Ethernet TSN, 5G New Radio (NR) and 802.11 (WiFi) are the primary candidates for enabling wireless TSN applications. In the TSN context, precise time synchronization represents a funda-mental building block. In this paper, we focus on the assessment of the synchronization accuracy of IEEE 1588 (PTP) over 5G NR networks by considering different network configurations and traffic loads. The results provide preliminary insights into the performance of PTP over 5G NR and its suitability for TSN applications.
Alberto Morato, Elena Ferrari 0002, Claudio Zunino, Manuel Cheminod, Stefano Vitturi, Federico Tramarin
ETFA4
2024 Redundancy for MQTT Communication: An Evolution
abstract
Critical infrastructure, utilities, and large enter-prises are increasingly complex. These sprawling systems, often geographically dispersed, rely on seamless coordination across vast networks. Typically, they use the internet and TCPIIP proto-cols for communication. However, ensuring system-level resilience requires exceptionally dependable network infrastructure. This paper proposes a solution built on a redundant version of the MQTT protocol, implemented directly at the network's endpoints. This approach ensures reliable communication even in the face of potential network issues. Additionally, the paper explores the potential for a future solution that analyzes multi-publisher/subscriber scenarios and, for this purpose, a prelimi-nary research on synchronizing communication among a larger number of devices within the network. The paper concludes by detailing the proposed solution, evaluating its effectiveness, and validating its practicality through experimentation.
Claudio Zunino, Manuel Cheminod, Gianluca Cena, Stefano Vitturi, Alberto Morato, Elena Ferrari 0002, Federico Tramarin
ETFA2
2024 Time-Sensitive Networking and Software-Defined Networking: An Experimental Setup for Realistic Performances
abstract
The ever more used and widespread Time-Sensitive Networking (TSN) has changed real-time networks, enabling reliable communication for time-critical applications. At the same time Software-Defined Networking (SDN) has emerged as a solution to ensure proper quality of service for managing dynamic network configurations even in evolving topologies. This paper investigates the integration between TSN and SDN to enable dynamic network re-configuration and improve performance for time-critical applications. We present an experimental setup designed to evaluate this approach. The setup focuses on scenarios where an SDN controller can dynamically reroute critical data flows across different TSN network devices to avoid interference and maintain consistent Quality-of-Service (QoS).
Claudio Zunino, Manuel Cheminod, Stefano Vitturi, Alberto Morato, Elena Ferrari 0002, Dave Cavalcanti 0001, Susruth Sudhakaran, Federico Tramarin
ETFA2
2023 Evaluating the Integration of Wireless Time-Sensitive Networking with Software-Defined Networking for Dynamic Network Configuration
abstract
The introduction of Time-Sensitive Networking (TSN) is revolutionizing real-time networks and time-critical applications. Recent advancements in this field extended the TSN capabilities to wireless technologies, giving rise to the concept of wireless TSN (WTSN). This paper focuses on the integration of wireless TSN with Software-Defined Networking (SDN) to enable dynamic network configuration and improve the performance of time-sensitive applications. We present a practical test environment that uses a hybrid network configuration consisting of wireless and wired TSN links. The primary objective is to evaluate the effectiveness of combining a TSN-capable network with an SDN controller. This setup enables dynamic configuration and routing within the system, allowing for prompt actions to address network issues, such as seamlessly re-routing data paths between the two links due to an increase in latency or packet loss. A measurement setup using OpenVSwitch in the wireless TSN domain is presented, along with the evaluation of time synchronization and dynamic route selection capabilities.
Alberto Morato, Claudio Zunino, Manuel Cheminod, Stefano Vitturi, Dave Cavalcanti 0001, Susruth Sudhakaran, Federico Tramarin
ETFA3
2023 Static Analysis of Packet Forwarding and Filtering Configurations in Industrial Networks
abstract
Securing industrial networked infrastructures has become increasingly important since the growth in their connectivity brought by production digitalization and the diffusion of paradigms such as Industrial Internet of Things (IIoT). Network segmentation is considered best practice to protect these networks from outside/inside cyber-attacks. To this purpose, network devices equipped with forwarding/filtering capabilities need to be suitably configured and deployed for the enforcement of segment-related security policies. Configuration of these devices in today industrial networked infrastructures is typically the result of a mix of manual and automated processes and, given the heterogeneity of devices and configuration languages, as well as of the supported applications and related requirements, it is often hard to make sure of its correctness and impact, e.g., on traffic latency. In this paper, a model is proposed to jointly describe network forwarding and filtering configuration. Techniques are then provided to perform static analyses such as verification of reachability intents and configuration equivalence, as well as the estimation of the latency introduced for handling specific traffic.
Manuel Cheminod, Lucia Seno
WFCS1
2022 Open-source firewalls for industrial applications: a laboratory study of Linux IPFire behavior*
abstract
Open-source software firewalls are becoming a viable solution to protect industrial networked systems and critical infrastructures. In fact, the adoption of technologies and devices originally conceived for general purpose computer networks and the consumer market has been proven to both reduce costs and enhance performance also in the industrial scenario. The goal of this paper is to start investigating the behavior of Linux IPFire in the light of its possible adoption in industrial applications and to provide a baseline for the development of techniques designed to improve the filtering capabilities in multi-firewall networks.
Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Lucia Seno, Adriano Valenzano
IECON1
2022 Improving performance and cyber-attack resilience in multi-firewall industrial networks
abstract
Firewalls are popular cyber-security countermea-sures that are increasingly used in industrial environments to protect the network infrastructure from attacks and malicious behavior. Unfortunately, they can also become inadvertent bot-tlenecks when the traffic load they have to filter grows larger. Among the different solutions that have been proposed to mitigate this aspect and improve performance of devices, rule migration looks appealing also in industrial multi-firewall systems because, differently from other techniques appeared in the literature, it neither requires interventions on the network topology nor it is based on non-standard packet formats and protocols. This paper is aimed at presenting some preliminary results about performance achievable with the rule migration approach, when it is applied to the popular Iptables open source firewall, in the light of its possible adoption in industrial application scenarios.
Lucia Seno, Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Adriano Valenzano
WFCS2
2019 A comprehensive approach to the automatic refinement and verification of access control policies
Manuel Cheminod, Luca Durante, Lucia Seno, Fulvio Valenza, Adriano Valenzano
Comput. Secur.1
2018 Performance Evaluation and Modeling of an Industrial Application-Layer Firewall
abstract
The availability of performance studies and simple models for firewalls able to deal with industrial application-layer communication protocols, such as Modbus/TCP, is crucial when the impact of these devices has to be estimated, even roughly, before their actual deployment in industrial networks. Unfortunately, most manufacturers do not provide this kind of information for commercial off-the-shelf available products. Thus, a viable solution is the development and experimental validation of simple models that can be used by designers to predict those firewall characteristics not explicitly related to their security capabilities. As an example, latency introduced on message forwarding is an aspect of significant interest in many industrial control systems, where delays and jitters in data delivery can severely impact on the effectiveness of the control actions. This paper reports on our experience in developing a performance model for a commercial device able to perform advanced application-layer filtering, in particular of Modbus/TCP traffic. A set of ad hoc designed experiments, performed by means of a purposely developed laboratory testbed, enabled both model development and validation, confirming a good correspondence of the estimated performance with the device actual behavior.
Manuel Cheminod, Luca Durante, Lucia Seno, Adriano Valenzano
IEEE Trans. Ind. Informatics1
2017 Detection of attacks based on known vulnerabilities in industrial networked systems
Manuel Cheminod, Luca Durante, Lucia Seno, Adriano Valenzano
J. Inf. Secur. Appl.1
2016 Performance impact of commercial industrial firewalls on networked control systems
abstract
The connection of control and process networks to company infrastructures and the Internet, besides offering undeniable advantages, also imposes the adoption of adequate security countermeasures. Specialized firewalls, able to recognize and inspect traffic concerning peculiar communication protocols such as Modbus, which are commonly adopted in industrial applications, are beginning to spread on the market. However, several industrial control systems (ICSs) must satisfy critical performance and timing requirements and the impact of introducing such a kind of devices in an existing network should be evaluated carefully. In this paper we present a simple approach based on ordinary equipment and open source software, which can help system designers and managers to get approximate but useful information about effects produced by including an industrial firewall in their system. The proposed technique, though quite simple, has the advantage of circumventing the need of ad-hoc measurement instrumentation and can be used also by non-experts, virtually with little or no effort, to get rough guess indications about the extent the firewall insertion in the network can be tolerated.
Manuel Cheminod, Luca Durante, Adriano Valenzano, Claudio Zunino
ETFA1
2015 Semiautomated Verification of Access Control Implementation in Industrial Networked Systems
abstract
Access control is a necessary building block in the security of any kind of cyber system and, in this sense, industrial networked systems (INSs) make no exception. Typically, access control policies are specified at a high implementation-independent level of abstraction and then mapped onto the real system by leveraging available policy enforcement mechanisms. Unfortunately, different from general-purpose ICT systems, enforcement mechanisms are generally very basic in INS. As a consequence, verifying the correctness of policy implementation becomes a crucial task, especially cumbersome when it needs to be carried out entirely by hand. This paper presents a new methodology, which also serves as the basis of a purposely developed software tool conceived to cope with the lack of policy enforcement mechanisms in INS and to allow semiautomatic verification of policy implementation. Our approach is based on a twofold system model that enables both the abstract specification of access control policies and the detailed description of the target physical system. These two separate views are then combined to automatically determine whether the current system implementation matches the policy specification.
Manuel Cheminod, Luca Durante, Lucia Seno, Adriano Valenzano
IEEE Trans. Ind. Informatics1
2013 Policy implementation check in industrial networks
abstract
Security of industrial network is a hot topic that requires constant efforts. Access control models and related analysis are powerful tools for the design and verification of security policies. However, the methodologies developed in the standard ICT world are not always suitable for the application in industrial environments because of the well known limitations that these systems are constantly dealing with.We propose here an approach for the automatic verification of the implementation of security policies in industrial systems with a particular attention on the limited security mechanisms available in these environments. We leverage a formal class model suitable for the description of system device configurations and the related security policies.
Manuel Cheminod
INDIN1
2013 Review of Security Issues in Industrial Networks
abstract
Although awareness is constantly rising, that industrial computer networks (in a very broad sense) can be exposed to serious cyber threats, many people still think that the same countermeasures, developed to protect general-purpose computer networks, can be effectively adopted also in those situations where a physical system is managed/controlled through some distributed Information and Communication Technology (ICT) infrastructure. Unfortunately, this is not the case, as several examples of successful attacks carried out in the last decade, and more frequently in the very recent past, have dramatically shown. Experts in this area know very well that often the peculiarities of industrial networks prevent the adoption of classical approaches to their security and, in particular, of those popular solutions that are mainly based on a detect and patch philosophy. This paper is a contribution, from the security point of view, to the assessment of the current situation of a wide class of industrial distributed computing systems. In particular, the analysis presented in this paper takes into account the process of ensuring a satisfactory degree of security for a distributed industrial system, with respect to some key elements such as the system characteristics, the current state of the art of standardization and the adoption of suitable controls (countermeasures) that can help in lowering the security risks below a predefined, acceptable threshold.
Manuel Cheminod, Luca Durante, Adriano Valenzano
IEEE Trans. Ind. Informatics1
2012 Modeling Emergency Response Plans with Coloured Petri Nets
Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Adriano Valenzano
CRITIS1
2011 Formal Vulnerability Analysis of a Security System for Remote Fieldbus Access
abstract
As fieldbus networks are becoming accessible from the Internet, security mechanisms to grant access only to authorized users and to protect data are becoming essential. This paper proposes a formally based approach to the analysis of such systems, both at the security protocols level and at the system architecture level. This multilevel analysis allows the evaluation of the effects of an attack on the overall system, due to security problems that affect the underlying security protocols. A case study on a typical fieldbus security system validates the approach.
Manuel Cheminod, Alfredo Pironti 0001, Riccardo Sisto
IEEE Trans. Ind. Informatics1
2009 Detecting Chains of Vulnerabilities in Industrial Networks
abstract
In modern factories, personal computers are starting to replace traditional programmable logic controllers, due to cost and flexibility reasons, and also because their operating systems now support programming environments even suitable for demanding real-time applications. These characteristics, as well as the ready availability of many software packages covering any kind of needs, have made the introduction of PC-based devices at the factory field level especially attractive. However, this approach has a profound influence on the extent of threats that a factory computing infrastructure shall be prepared to deal with. In fact, industrial personal computers share the same kinds of vulnerabilities with their office automation counterparts. Then, their introduction increases the risk of cyber-attacks. As the complexity of the network grows, the problem rapidly becomes hard to tackle by hand, due to the subtle and unforeseen interactions that may occur among apparently unrelated vulnerabilities, thus bearing the focus on the full automation of the analysis. Going into this direction, this paper presents a software tool that, given an accurate and machine-readable description of vulnerabilities, detects whether or not they are of concern and evaluates consequences in the context of a factory network.
Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Paolo Maggi, Davide Pozza, Riccardo Sisto, Adriano Valenzano
IEEE Trans. Ind. Informatics1