EDBT 2026 Demo / reviewers in the wild / expert
Luca Caviglione
dblp:76/6202
· DBLP profile ↗
44ranked-venue papers
14as first author
27since 2021 · last 2026
0000-0001-6466-3354ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 4 first-author · 11 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 6 since 2021Computer networks · 6 · 5 first-author · 2 since 2021Systems, architecture and hardware · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MalARN: An Adversarial Reconstruction Network for Improving Detection of Evolving Malware
Francesco Pasqualatto, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Giuseppe Manco 0001, Ettore Ritacco, Antonino Rullo |
ISMIS | 2 |
| 2026 | A survey of internet censorship and its measurement: Methodology, trends, and challengesabstractInternet censorship limits the access of nodes residing within a specific network environment to the public Internet, and vice versa. During the last decade, techniques for conducting Internet censorship have been developed further. Consequently, methodology for measuring Internet censorship had been improved as well. In this paper, we firstly provide a survey of network-level Internet censorship techniques. Secondly, we survey censorship measurement methodology. We further cover the censorship of circumvention tools and its measurement, as well as available datasets. In cases where it is beneficial, we bridge the terminology and taxonomy of Internet censorship with related domains, namely traffic obfuscation and information hiding. We further extend the technical perspective with recent trends and challenges, including human aspects of Internet censorship. Steffen Wendzel, Simon Volpert, Sebastian Zillien, Julia Lenz, Philip Rünz, Luca Caviglione |
Comput. Secur. | 6 |
| 2026 | Deobfuscation of JavaScript code and identification of security weaknesses through large language modelsabstractAdvancements in Large Language Models (LLMs) allow solving many challenging tasks related to software security in an automatic manner, e.g., the generation of test cases. An important aspect concerns the deobfuscation of source code, especially for improving its readability or preventing the elusion of signature-based countermeasures. Although LLMs are increasingly deployed to reveal the presence of malicious payloads within obfuscated software components, a comprehensive understanding of their potential and limitations is still missing. In this work, we evaluate the effectiveness of deobfuscating JavaScript code through an LLM-based pipeline. In more detail, we investigate whether LLMs can preserve structural properties of the software, especially to enhance the identification of weaknesses. Compared to two standard tools (i.e., JSNice and js-deobfuscator ), our approach provides a more readable JavaScript prose according to several metrics, while retaining information on the Common Weaknesses Enumeration plaguing the software. To support the process of explaining issues within code, we performed tests on the use of two general-purpose LLMs, i.e., ChatGPT and Google Gemini. Results indicate that advancing the security of JavaScript through LLMs requires facing several challenges, which can be largely addressed via ad-hoc models. Giacomo Benedetti, Luca Caviglione, Carmela Comito, Alberto Falcone, Massimo Guarascio 0001 |
Future Gener. Comput. Syst. | 2 |
| 2026 | A deep learning-based approach for stegomalware sanitization in digital imagesabstractAbstract Malware is increasingly endowed with steganographic mechanisms for concealing malicious data to avoid detection or bypass security measures. As a result, an emerging wave of threats named stegomalware has started to rise. Among the various approaches, real-world stegomalware primarily hides information within digital images, for instance, to retrieve additional payloads or configuration data. Unfortunately, developing attack-agnostic mitigation tools is difficult, especially due to the tight relation between the image format and the steganographic technique. Therefore, this paper presents an autoencoder-based approach to perform sanitization , i.e., to disrupt the malicious content hidden in images without altering their visual quality. For this purpose, we used an enhanced U-Net-like neural architecture, and we compared our idea against other mechanisms, including JPG transcoding and simple addition of Gaussian noise. Results obtained by considering different hiding patterns and realistic payloads showcased the effectiveness of our approach. Moreover, the U-Net-based sanitization solution prevents the recovery of the payload while preserving the original image quality and reducing risks arising from side-channel attacks. Angelica Liguori, Marco Zuppelli, Daniela Gallo, Massimo Guarascio 0001, Luca Caviglione |
J. Intell. Inf. Syst. | 5 |
| 2026 | Automated Membership Inference via Prompt-Based Attacks in Generative Models
Daniela Gallo, Angelica Liguori, Ettore Ritacco, Luca Caviglione, Fabrizio Durante, Giuseppe Manco 0001 |
Mach. Learn. | 4 |
| 2025 | Analysis and Detection of Android Stegomalware: the Impact of the Loading StageabstractDue to the increasing use of advanced offensive techniques, the mitigation of Android malware is an urgent need.An emerging attack trend exploits steganography to conceal malicious payloads within applications to make attacks stealthier.Even if works on "stegomalware" are starting to emerge, they primarily focus on the multimedia part of the attack chain, i.e., on how to detect hidden data in images or videos.Therefore, this work aims at understanding whether the loading stage required for the extraction of cloaked information can generate detection signatures.To this aim, we develop a proofof-concept implementation, which has been repacked within a real Android application and tested against several malware detection engines provided by VirusTotal.To anticipate possible offensive campaigns, we also performed tests by considering threat actors able to obfuscate the bytecode of the loader or the entire APK.Results indicate that standard tools are not ready to face stegomalware targeting Android applications.Therefore, we provide indications on how to improve forensics and attribution phases for Android malware endowed with information hiding capabilities. Diego Soi, Silvia Lucia Sanna, Giacomo Benedetti, Angelica Liguori, Leonardo Regano, Luca Caviglione, Giorgio Giacinto |
IH&MMSec | 6 |
| 2024 | Investigating HTTP Covert Channels Through Fuzz TestingabstractModern malware increasingly deploys network covert channels to prevent detection or bypass firewalls. Unfortunately, the early discovery of protocol fields and functional behaviors of traffic that can be abused to conceal information is very challenging. In this perspective, fuzz testing could help to face the tight relationship between the used hiding scheme and the targeted protocol trait. Even if fuzzing is a well-established practice to reveal implementation issues, bugs, or unhandled behaviors, it has never been considered to assess the “susceptilibility” of protocols to covert communications. Kai Hölk, Wojciech Mazurczyk, Marco Zuppelli, Luca Caviglione |
ARES | 4 |
| 2024 | No Country for Leaking Containers: Detecting Exfiltration of Secrets Through AI and SyscallsabstractContainers offer lightweight execution environments for implementing microservices or cloud-native applications. Owing to their ubiquitous diffusion jointly with the complex interplay of hardware, computing, and network resources, effectively enforcing container security is a difficult task. Specifically, runtime detection of threats poses many challenges since container images are often immutable, and many malware deploys obfuscation or elusive mechanisms. Therefore, in this work, we propose a deep-learning-based approach for identifying the presence of two containers colluding to covertly leak secret information. In more detail, we consider a threat actor trying to exfiltrate a 4,096-bit private TLS key via five different covert channels. To decide whether containers are colluding for leaking data, the deep learning model is fed with statistical indicators of the syscalls, which are built starting from simple counters. Results indicate the effectiveness of our approach, even if some adjustments are needed to reduce the number of false positives. Marco Zuppelli, Massimo Guarascio 0001, Luca Caviglione, Angelica Liguori |
ARES | 3 |
| 2024 | Erasing the Shadow: Sanitization of Images with Malicious Payloads Using Deep Autoencoders
Angelica Liguori, Marco Zuppelli, Daniela Gallo, Massimo Guarascio 0001, Luca Caviglione |
ISMIS | 5 |
| 2024 | Mitigation of Covert Communications in MQTT Topics Through Small Language ModelsabstractModern IoT ecosystems face many security issues. An aspect often neglected concerns covert channels, which allow for exfiltrating data or preventing detection. To this aim, the Message Queuing Telemetry Transport (MQTT) protocol can be abused to create various hidden communication paths, mainly due to its textual nature. Alas, simpler detection metrics could be ineffective and their optimization requires a vast number of test cases. Therefore, this paper proposes to use a small language model trained over real MQTT topics to automatically generate the required test cases. Results indicate the need for optimizations to make popular detection metrics usable “in the wild”. Camilla Cespi Polisiani, Marco Zuppelli, Mariacarla Calzarossa, Luca Caviglione, Massimo Guarascio 0001 |
MASCOTS | 4 |
| 2024 | Learning autoencoder ensembles for detecting malware hidden communications in IoT ecosystemsabstractAbstract Modern IoT ecosystems are the preferred target of threat actors wanting to incorporate resource-constrained devices within a botnet or leak sensitive information. A major research effort is then devoted to create countermeasures for mitigating attacks, for instance, hardware-level verification mechanisms or effective network intrusion detection frameworks. Unfortunately, advanced malware is often endowed with the ability of cloaking communications within network traffic, e.g., to orchestrate compromised IoT nodes or exfiltrate data without being noticed. Therefore, this paper showcases how different autoencoder-based architectures can spot the presence of malicious communications hidden in conversations, especially in the TTL of IPv4 traffic. To conduct tests, this work considers IoT traffic traces gathered in a real setting and the presence of an attacker deploying two hiding schemes (i.e., naive and “elusive” approaches). Collected results showcase the effectiveness of our method as well as the feasibility of deploying autoencoders in production-quality IoT settings. Nunzio Cassavia, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Marco Zuppelli |
J. Intell. Inf. Syst. | 2 |
| 2023 | Information Leakages of Docker Containers: Characterization and Mitigation StrategiesabstractCompared to classic virtual machines, containers offer lightweight and dynamic execution environments. Hence, they are core building blocks for the development of future softwarized networks and cloud-native applications. However, containers still pose many security challenges, which are less understood compared to other virtualization paradigms. An important aspect often neglected concerns techniques enabling containers to leak data outside their execution perimeters, e.g., to exfiltrate sensitive information or coordinate attacks. In this paper we investigate security impacts of covert communications based on the looser isolation of memory statistics information. Our characterization indicates that the investigation of system calls should be considered a prime tool to reveal the presence of collusive attack schemes. We also elaborate on two mitigation techniques: the first entails prevention via “hardening” configurations of containers, while the second implements a run-time disruption mechanism. Marco Zuppelli, Matteo Repetto, Luca Caviglione, Enrico Cambiaso |
NetSoft | 3 |
| 2022 | Detection of Malicious Images in Production-Quality Scenarios with the SIMARGL ToolkitabstractAn increasing trend exploits steganography to conceal payloads in digital images, e.g., to drop malicious executables or to retrieve configuration files. Due to the very attack-specific nature of the exploited hiding mechanisms, developing general detection methods is a hard task. An effective approach concerns the creation of ad-hoc solutions to be integrated within general toolkits, also to holistically face unknown threats. Therefore, this paper discusses the integration of a tool for detecting malicious contents hidden in digital images via the Invoke-PSImage technique within the Secure Intelligent Methods for Advanced Recognition of Malware and Stegomalware framework. Since the real impact of images embedding steganographic threats and the behavior of ad-hoc solutions in realistic scenarios are still unknown territories, this work also showcases a performance evaluation conducted in a nation-wide telecommunication provider. Results demonstrated the effectiveness of the approach and also support the need of modular architectures to face the emerging wave of highly-specialized threats. Luca Caviglione, Martin Grabowski, Kai Gutberlet, Adrian Marzecki, Marco Zuppelli, Andreas Schaffhauser, Wojciech Mazurczyk |
ARES | 1 |
| 2022 | Revealing MageCart-like Threats in Favicons via Artificial IntelligenceabstractModern malware increasingly takes advantage of information hiding to avoid detection, spread infections, and obfuscate code. A major offensive strategy exploits steganography to conceal scripts or URLs, which can be used to steal credentials or retrieve additional payloads. A recent example is the attack campaign against the Magento e-commerce platform, where a web skimmer has been cloaked in favicons to steal payment information of users. Massimo Guarascio 0001, Marco Zuppelli, Nunzio Cassavia, Luca Caviglione, Giuseppe Manco 0001 |
ARES | 4 |
| 2022 | Ensembling Sparse Autoencoders for Network Covert Channel Detection in IoT Ecosystems
Nunzio Cassavia, Luca Caviglione, Massimo Guarascio 0001, Angelica Liguori, Marco Zuppelli |
ISMIS | 2 |
| 2022 | Emerging topics in defending networked systems
Steffen Wendzel, Wojciech Mazurczyk, Luca Caviglione, Amir Houmansadr |
Future Gener. Comput. Syst. | 3 |
| 2022 | Code Layering for the Detection of Network Covert Channels in Agentless SystemsabstractThe growing interest in agentless and serverless environments for the implementation of virtual/container network functions makes monitoring and inspection of network services challenging tasks. A major requirement concerns the agility of deploying security agents at runtime, especially to effectively address emerging and advanced attack patterns. This work investigates a framework leveraging the extended Berkeley Packet Filter to create ad-hoc security layers in virtualized architectures without the need of embedding additional agents. To prove the effectiveness of the approach, we focus on the detection of network covert channels, i.e., hidden/parasitic network conversations difficult to spot with legacy mechanisms. Experimental results demonstrate that different types of covert channels can be revealed with a good accuracy while using limited resources compared to existing cybersecurity tools (i.e., Zeek and libpcap). Marco Zuppelli, Matteo Repetto, Andreas Schaffhauser, Wojciech Mazurczyk, Luca Caviglione |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2021 | Risks and Opportunities for Information Hiding in DICOM StandardabstractThe increasing application of ICT technologies to medicine opens new usage patterns. Among the various standards, the Digital Imaging and COmmunication in Medicine (DICOM) has been gaining momentum, mainly due to its complete coverage of the diagnostic pipeline, including key applications such as CT, MRI and ultrasound scanners. However, owing to its complex and multifaceted nature, DICOM is prone to many risks especially due to the vast and complex attack surface characterizing the composite interplay of services, formats and technologies at the basis of the standard. Luckily, DICOM exhibits some room for improving its security. Specifically, information hiding and steganography can be used in a twofold manner. On one hand, they can help to watermark diagnostic images to improve their resistance against tampering and alterations. On the other hand, the digital infrastructure at the basis of DICOM can lead to data leaks or malicious manipulations via artificial intelligence techniques. Therefore, in this work we introduce risks and opportunities when applying information-hiding-based techniques to the DICOM standard. Our investigation highlights some opportunities as well as introduces possibilities of exploiting DICOM images to set up covert channels, i.e., hidden communication paths that can be used to exfiltrate data or launch attacks. To prove the effectiveness of our vision, this paper also showcases the performance evaluation of a covert channel built by applying text steganography principles on realistic DICOM images. Aleksandra Mileva, Luca Caviglione, Aleksandar Velinov, Steffen Wendzel, Vesna Dimitrova |
ARES | 2 |
| 2021 | bccstego: A Framework for Investigating Network Covert ChannelsabstractModern malware increasingly exploits information hiding to remain undetected while attacking. To this aim, network covert channels, i.e., hidden communication paths established within legitimate flows, can be used to exfiltrate data or exchange commands without getting noticed by firewalls, antivirus, and intrusion detection systems. Since the secret data can be directly injected in various portions of the stream or encoded via suitable alterations of the traffic, spotting hidden communications is a challenging and poorly generalizable task. Moreover, the majority of works addressed IPv4, thus leaving the detection of covert channels targeting IPv6 almost unexplored. Matteo Repetto, Luca Caviglione, Marco Zuppelli |
ARES | 2 |
| 2021 | Crème de la Crème: Lessons from Papers in Security PublicationsabstractThe number of citations attracted by publications is a key criteria for measuring their success. To avoid discriminating newer research, such a metric is usually measured in average yearly citations. Understanding and characterizing how citations behave have been prime research topics, yet investigations targeting the cybersecurity domain seem to be particularly scarce. In this perspective, the paper aims at filling this gap by analyzing average yearly citations for 6,693 papers published in top-tier conferences and journals in cybersecurity. Results indicate the existence of three clusters, i.e., general security conferences, general security journals, and cryptography-centered publications. The analysis also suggests that the amount of conference-to-conference citations stands out compared to journal-to-journal and conference-to-journal citations. Besides, papers published at top conferences attract more citations although a direct comparison against other venues is not straightforward. To better quantify the impact of works dealing with cybersecurity aspects, the paper introduces two new metrics, namely the number of main words in the title, and the combined number of unique main words in title, abstract and keywords. Collected results show that they can be associated with average yearly citations (together with the number of cited references). Finally, the paper draws some ideas to take advantage from such findings. Simon Vrhovec, Luca Caviglione, Steffen Wendzel |
ARES | 2 |
| 2021 | A Revised Taxonomy of Steganography Embedding PatternsabstractSteganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography. Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert |
ARES | 2 |
| 2021 | pcapStego: A Tool for Generating Traffic Traces for Experimenting with Network Covert ChannelsabstractThe increasing diffusion of malware endowed with steganographic and cloaking capabilities requires tools and techniques for conducting research activities, testing real deployments and elaborating mitigation mechanisms. To investigate attacks targeting network and appliances, a core requirement concerns the availability of suitable traffic traces, which can be used to derive mathematical models for simulation or to develop machine-learning-based countermeasures. Unfortunately, the young nature of threats injecting secrets or cloaking their presence within network traffic, the high protocol-dependent nature of the various embedding processes, and privacy issues, prevent the vast diffusion of datasets to perform research. Therefore, in this paper we present pcapStego, a tool for creating network covert channels within .pcap files. This approach has two major advantages: it allows to prepare large datasets starting from real network traces, and it generates “replayable” conversations useful for both emulating attacks or conduct pentesting campaigns. To prove the effectiveness of the tool, we showcase the generation of network covert channels targeting IPv6 traffic, which is gaining momentum and it is expected to be a major target for future attacks. Marco Zuppelli, Luca Caviglione |
ARES | 2 |
| 2021 | Code Augmentation for Detecting Covert Channels Targeting the IPv6 Flow LabelabstractInformation hiding is at the basis of a new-wave of malware able to elude common detection mechanisms or remain unnoticed for long periods. To this aim, a key approach exploits network covert channels, i.e., abusive communication paths nested within a legitimate traffic flow. The increasing diffusion of IPv6 makes it attractive for an attacker, especially for the presence of the Flow Label field, which can be manipulated to contain up to 20 secret bits per packet. Unfortunately, gathering data to implement a standalone detection mechanism or to support third-party security tools is a poorly generalizable process and often leads to scalability issues. This paper showcases how to take advantage of code augmentation features (i.e., the extended Berkeley Packet Filter) to detect covert channels targeting the IPv6 Flow Label. To prove its effectiveness, the proposed approach has been tested against Internet-wide traffic traces collected in the wild. Results indicate that it is possible to spot the channel while mitigating the memory footprint and the computational burden (e.g., the processed traffic only experience an additional delay of a few nanoseconds). Luca Caviglione, Marco Zuppelli, Wojciech Mazurczyk, Andreas Schaffhauser, Matteo Repetto |
NetSoft | 1 |
| 2021 | Kernel-level tracing for detecting stegomalware and covert channels in Linux environmentsabstractModern malware is becoming hard to spot since attackers are increasingly adopting new techniques to elude signature- and rule-based detection mechanisms. Among the others, steganography and information hiding can be used to bypass security frameworks searching for suspicious communications between processes or exfiltration attempts through covert channels. Since the array of potential carriers is very large (e.g., information can be hidden in hardware resources, various multimedia files or network flows), detecting this class of threats is a scarcely generalizable process and gathering multiple behavioral information is time-consuming, lacks scalability, and could lead to performance degradation. In this paper, we leverage the extended Berkeley Packet Filter (eBPF), which is a recent code augmentation feature provided by the Linux kernel, for programmatically tracing and monitoring the behavior of software processes in a very efficient way. To prove the flexibility of the approach, we investigate two realistic use cases implementing different attack mechanisms, i.e., two processes colluding via the alteration of the file system and hidden network communication attempts nested within IPv6 traffic flows. Our results show that even simple eBPF programs can provide useful data for the detection of anomalies, with a minimal overhead. Furthermore, the flexibility to develop and run such programs allows to extract relevant features that could be used for the creation of datasets for feeding security frameworks exploiting AI. Luca Caviglione, Wojciech Mazurczyk, Matteo Repetto, Andreas Schaffhauser, Marco Zuppelli |
Comput. Networks | 1 |
| 2021 | Deep reinforcement learning for multi-objective placement of virtual machines in cloud datacentersabstractAbstract The ubiquitous diffusion of cloud computing requires suitable management policies to face the workload while guaranteeing quality constraints and mitigating costs. The typical trade-off is between the used power and the adherence to a service-level metric subscribed by customers. To this aim, a possible idea is to use an optimization-based placement mechanism to select the servers where to deploy virtual machines. Unfortunately, high packing factors could lead to performance and security issues, e.g., virtual machines can compete for hardware resources or collude to leak data. Therefore, we introduce a multi-objective approach to compute optimal placement strategies considering different goals, such as the impact of hardware outages, the power required by the datacenter, and the performance perceived by users. Placement strategies are found by using a deep reinforcement learning framework to select the best placement heuristic for each virtual machine composing the workload. Results indicate that our method outperforms bin packing heuristics widely used in the literature when considering either synthetic or real workloads. Luca Caviglione, Mauro Gaggero, Massimo Paolucci 0002, Roberto Ronco |
Soft Comput. | 1 |
| 2021 | Correction to: Deep reinforcement learning for multi-objective placement of virtual machines in cloud datacentersabstractPage 2: Column 2, lines 2-4, previously read: “Specifically, we consider a decision maker that, after a proper training, is able to select the most suitable heuristic for compute the placement for each VM requested by end users”. Luca Caviglione, Mauro Gaggero, Massimo Paolucci 0002, Roberto Ronco |
Soft Comput. | 1 |
| 2021 | Multiobjective Placement for Secure and Dependable Smart Industrial EnvironmentsabstractCyber-physical systems allow to implement efficient, highly automated, and green smart industrial environments. To this aim, computation is a critical asset to control machineries, process data, and run proper optimization strategies. In general, computing capabilities are provided by virtualizing resources of local devices or servers deployed in a remote datacenter. Thus, their management is crucial for the security of the cyber-physical ecosystem or to engineer dependable industrial environments. In this article, we introduce a placement mechanism to pursue various security and dependability goals, such as preventing information leakages, providing redundancy, counteracting hardware outages or software aging, avoiding privacy breaks, and mitigating wastage of resources and energy. Multiobjective placement actions are computed by solving suitable mathematical programming problems with competing objectives. Simulations performed using real workload traces showcase the effectiveness of the approach in comparison with bin-packing-based heuristics. Luca Caviglione, Mauro Gaggero |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | Stegomalware detection through structural analysis of media filesabstractThe growing diffusion of malware is causing non-negligible economic and social costs. Unfortunately, modern attacks evolve and adapt to defensive mechanisms, and many threats are designed for the optimal exploitation of the traits of the victims. Thus, phenomena such as mobile malware, fileless malware or stegomalware are becoming widespread and represent the next variations of malicious attacks that have to be faced. In particular, the massive amount of digital content shared on the Internet is increasingly more often being used by attackers for the injection of malicious code to bypass security tools or prevent detection. Damian Puchalski, Luca Caviglione, Rafal Kozik, Adrian Marzecki, Slawomir Krawczyk, Michal Choras |
ARES | 2 |
| 2020 | Design and performance evaluation of reversible network covert channelsabstractCovert channels nested within network traffic are important tools for allowing malware to act unnoticed or to stealthily exchange and exfiltrate information. Thus, understanding how to detect or mitigate their utilization is of paramount importance, especially to counteract the rise of increasingly sophisticated threats. In this perspective, the literature proposed various approaches, including distributed wardens, which can be used to collect traffic in different portions of the network and compare the samples to check for discrepancies revealing hidden communications. However, the use of some form of reversibility, i.e., being able to restore the exploited network carrier to its original form before the injection, can challenge such a detection scheme. Therefore, in this work we introduce and evaluate the performances of different techniques used to endow network covert channels with reversibility. Results indicate the feasibility of achieving reversibility but the used protocol plays a major role. Przemyslaw Szary, Wojciech Mazurczyk, Steffen Wendzel, Luca Caviglione |
ARES | 4 |
| 2020 | Programmable Data Gathering for Detecting StegomalwareabstractThe “arm race” against malware developers requires to collect a wide variety of performance measurements, for instance to face threats leveraging information hiding and steganography. Unfortunately, this process could be time-consuming, lack of scalability and cause performance degradations within computing and network nodes. Moreover, since the detection of steganographic threats is poorly generalizable, being able to collect attack-independent indicators is of prime importance. To this aim, the paper proposes to take advantage of the extended Berkeley Packet Filter to gather data for detecting stegomalware. To prove the effectiveness of the approach, it also reports some preliminary experimental results obtained as the joint outcome of two H2020 Projects, namely ASTRID and SIMARGL. Alessandro Carrega, Luca Caviglione, Matteo Repetto, Marco Zuppelli |
NetSoft | 2 |
| 2020 | VoIP network covert channels to enhance privacy and information sharingabstractInformation hiding is increasingly used to implement covert channels, to exfiltrate data or to perform attacks in a stealthy manner. Another important usage deals with privacy, for instance, to bypass limitations imposed by a regime, to prevent censorship or to share information in sensitive scenarios such as those dealing with cyber defense. In this perspective, the paper investigates how VoIP communications can be used as a methodology to enhance privacy. Specifically, we propose to hide traffic into VoIP conversations in order to prevent the disclosure, exposure and revelation to an attacker or blocking the ongoing exchange of information. To this aim, we exploit the voice activity detection feature available in many client interfaces to produce fake silence packets, which can be used as the carrier where to hide data. Results indicate that the proposed approach can be suitable to enforce the privacy in real use cases, especially for file transfers. As interactive services (e.g., web browsing) may experience too many delays due to the limited bandwidth, some form of optimization or content scaling may be advisable for such scenarios. Jens Saenger, Wojciech Mazurczyk, Jörg Keller 0001, Luca Caviglione |
Future Gener. Comput. Syst. | 4 |
| 2019 | Towards Reversible Storage Network Covert ChannelsabstractThe use of network covert channels to improve privacy or support security threats has been widely discussed in the literature. As today, the totality of works mainly focuses on how to not disrupt the overt traffic flow and the performance of the covert channels in terms of undetectability and capacity. To not void the stealthiness of the channel, an important feature is the ability of restoring the carrier embedding the secret information into its original form. However, the development of such techniques mainly targets the domain of digital media steganography. Therefore, this paper applies the concept of reversible data hiding to storage network covert channels. To prove the effectiveness of our idea, a prototypical implementation of a channel exploiting IPv4 flows is presented along with its performance evaluation. Wojciech Mazurczyk, Przemyslaw Szary, Steffen Wendzel, Luca Caviglione |
ARES | 4 |
| 2019 | Model Predictive Control for Energy-Efficient, Quality-Aware, and Secure Virtual Machine PlacementabstractModern datacenters rely on virtualization to deliver complex and scalable cloud services. To avoid inflating costs or reducing the perceived service level, suitable resource optimization techniques are needed. Placement can be used to prevent inefficient maps between virtual and physical machines. In this perspective, we propose a holistic placement framework considering conflicting performance metrics, such as the service level delivered by the cloud, the energetic footprint, hardware or software outages, and security policies. Unfortunately, computing the best placement strategies is nontrivial, as it requires the ability to trade among several goals, possibly in a real-time manner. Therefore, we approach the problem via model predictive control to devise optimal maps between virtual and physical machines. Results show the effectiveness of our technique in comparison with classical heuristics. Mauro Gaggero, Luca Caviglione |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2018 | Exploiting IP telephony with silence suppression for hidden data transfers
Sabine S. Schmidt, Wojciech Mazurczyk, Radoslaw Kulesza, Jörg Keller 0001, Luca Caviglione |
Comput. Secur. | 5 |
| 2018 | Emerging and Unconventional: New Attacks and Innovative Detection TechniquesabstractArt. 9672523, 1 S. Luca Caviglione, Wojciech Mazurczyk, Steffen Wendzel, Sebastian Zander |
Secur. Commun. Networks | 1 |
| 2017 | A New Data-Hiding Approach for IP Telephony Applications with Silence SuppressionabstractEven if information hiding can be used for licit purposes, it is increasingly exploited by malware to exfiltrate data or to coordinate attacks in a stealthy manner. Therefore, investigating new methods for creating covert channels is fundamental to completely assess the security of the Internet. Since the popularity of the carrier plays a major role, this paper proposes to hide data within VoIP traffic. Specifically, we exploit Voice Activity Detection (VAD), which suspends the transmission during speech pauses to reduce bandwidth requirements. To create the covert channel, our method transforms a VAD-activated VoIP stream into a non-VAD one. Then, hidden information is injected into fake RTP packets generated during silence intervals. Results indicate that steganographically modified VAD-activated VoIP streams offer a good trade-off between stealthiness and steganographic bandwidth. Sabine S. Schmidt, Wojciech Mazurczyk, Jörg Keller 0001, Luca Caviglione |
ARES | 4 |
| 2017 | Covert Channels in Personal Cloud Storage Services: The Case of DropboxabstractPersonal storage services are one of the most popular applications based on the cloud computing paradigm. Therefore, the analysis of possible privacy and security issues has been a relevant part of the research agenda. However, threats arising from the adoption of information hiding techniques have been mainly neglected. In this perspective, the paper investigates how personal cloud storage services can be used for building covert channels for stealthy exchange of information through the Internet. To have a realistic use case, we consider the Dropbox application and we present the performance evaluation of two different covert communication methods. To understand the stealthiness of our approach and propose countermeasures, we also investigate some behaviors of Dropbox in a production quality deployment. Luca Caviglione, Maciej Podolski, Wojciech Mazurczyk, Massimo Ianigro |
IEEE Trans. Ind. Informatics | 1 |
| 2016 | Seeing the Unseen: Revealing Mobile Malware Hidden Communications via Energy Consumption and Artificial IntelligenceabstractModern malware uses advanced techniques to hide from static and dynamic analysis tools. To achieve stealthiness when attacking a mobile device, an effective approach is the use of a covert channel built by two colluding applications to exchange data locally. Since this process is tightly coupled with the used hiding method, its detection is a challenging task, also worsened by the very low transmission rates. As a consequence, it is important to investigate how to reveal the presence of malicious software using general indicators, such as the energy consumed by the device. In this perspective, this paper aims to spot malware covertly exchanging data using two detection methods based on artificial intelligence tools, such as neural networks and decision trees. To verify their effectiveness, seven covert channels have been implemented and tested over a measurement framework using Android devices. Experimental results show the feasibility and effectiveness of the proposed approach to detect the hidden data exchange between colluding applications. Luca Caviglione, Mauro Gaggero, Jean-François Lalande, Wojciech Mazurczyk, Marcin Urbanski |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | A survey on energy-aware security mechanisms
Alessio Merlo, Mauro Migliardi, Luca Caviglione |
Pervasive Mob. Comput. | 3 |
| 2011 | What is Green Security?abstractGreen Security is a new research field defining and investigating security solutions under an energy-aware perspective. Green Security aims at: (1) evaluating the actual security mechanisms in order to assess their energy consumption; (2) building new security mechanisms by considering energy costs from the design phase. In this paper, we first provide a definition of Green Security and formalism to model it, then we provide a use case showing how it is possible to model the energy consumption of two Intrusion Detection System (IDS) strategies, finally we leverage this model to assess the energy leakage due to the late discovery of bad packets. Luca Caviglione, Alessio Merlo, Mauro Migliardi |
IAS | 1 |
| 2011 | Design, optimization and performance evaluation of a content distribution overlay for streaming
Luca Caviglione, Cristiano Cervellera |
Comput. Commun. | 1 |
| 2008 | Optimization of an eMule-like modifier strategy
Luca Caviglione, Cristiano Cervellera, Franco Davoli, Filippo Aldo Grassia |
Comput. Commun. | 1 |
| 2008 | Traffic volume analysis of a nation-wide eMule community
Luca Caviglione, Franco Davoli |
Comput. Commun. | 1 |
| 2007 | Design of a peer-to-peer system for optimized content replication
Luca Caviglione, Cristiano Cervellera |
Comput. Commun. | 1 |