EDBT 2026 Demo / reviewers in the wild / expert
Barbara Carminati
dblp:83/2099
· DBLP profile ↗
92ranked-venue papers
29as first author
23since 2021 · last 2026
0000-0002-7502-4731ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 12 first-author · 11 since 2021Databases, data management, data science and information retrieval · 21 · 7 first-author · 2 since 2021Software engineering, systems software and programming languages · 13 · 4 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 10 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 8 · 2 first-authorComputer networks · 7 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AUTOMal: An LLM-Based Automated Feature Engineering Framework for Efficient Malware Detection at the EdgeabstractEdge computing supports real-time decision making and is crucial for applications such as the Internet of Things (IoT), autonomous systems, and smart manufacturing. Securing these devices against malware attacks is essential. Many machine learning (ML) based approaches for malware detection at the edge have been developed so far. However, at the initial stage, extracting features from raw data to train ML models remains a significant challenge, as it often requires substantial domain expertise and is time-consuming. Existing automated frameworks using traditional transformation techniques often fail to incorporate domain knowledge, attempt to transform all features, and frequently spend excessive time processing unnecessary ones. In this paper, we introduce a novel automated feature engineering framework for ML-based malware detection that exploits domain knowledge encoded in Large Language Models (LLMs) to identify subsets of features appropriate for specific transformations, thereby avoiding indiscriminate transformation of the entire dataset. Experimental results demonstrate that the proposed framework outperforms state-of-the-art methods on multiple IoT malware detection datasets. Moreover, the framework achieves a substantial reduction in computational overhead, exhibiting an approximate 90-fold improvement in processing efficiency relative to existing approaches. Nguyen Khanh Son, Christian Rondanini, Barbara Carminati, Elena Ferrari 0001 |
CODASPY | 3 |
| 2026 | PrivacyAssist: A User-Centric Agent Framework for Detecting Privacy Inconsistencies in Android Apps
Tran Thanh Lam Nguyen, Edoardo Di Tullio, Barbara Carminati, Elena Ferrari 0001 |
WISEC | 3 |
| 2026 | ALIBIS: Assessing and mitigating the risk of sensitive metadata Leakage In moBile Image SharingabstractSmartphones have become necessary in modern life and can replace traditional devices like cameras. The high demand for taking and sharing photos via smartphones, especially with the explosion of social networks and instant messaging, highlights the importance of smartphones. Android, the leading smartphone operating system, has continuously improved user security and privacy over its 17 years of development (2008–2025). However, security vulnerabilities still exist because of its open-source nature. This paper introduces ALIBIS, a framework that automatically estimates the risk of leakage of sensitive data contained in EXIF metadata when users share images online by combining static analysis and Large Language Models (LLMs). ALIBIS demonstrates consistent and robust estimation capabilities, achieving an average accuracy, precision, recall, and f1 score in k-fold cross-validation (k=5) of 0.8686, 0.8902, 0.881, and 0.8854, respectively. In addition, a survey of 130 global participants, including Android app developers and end-users, revealed a significant lack of awareness about image metadata and its risks: 82.3% of participants (user role) do not delete sensitive metadata before sharing images, and 62.3% do not know how to remove metadata. Furthermore, only 1.9% of participants (developer role) proactively remove EXIF metadata during programming. We propose ExifMetadataLib, a lightweight library for easy integration with Android OS, to mitigate sensitive metadata leakage. Tran Thanh Lam Nguyen, Barbara Carminati, Elena Ferrari 0001 |
Pervasive Mob. Comput. | 2 |
| 2026 | Big Data-Driven UAV Regulatory Compliance: Frameworks, Challenges, and OpportunitiesabstractUnmanned aerial vehicles (UAVs) are increasingly integral to various applications, generating vast data like high resolution imagery and environmental metrics, yet they face challenges in real-time regulatory compliance. As a vision paper, UAVSync-BD proposes a conceptual synchronization process, with implementation details, testbeds, and datasets deferred to future research for reproducibility. This position paper conducts a meta-analysis of UAV technology, compares regional regulations, and proposes a reference architecture for a Big Data framework leveraging distributed processing, edge computing, and AI-driven analytics to ensure UAV regulatory compliance. It also discusses open research challenges in the field. Huu Phuoc Dai Nguyen, Khaoula Hidawi, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Big Data | 3 |
| 2026 | Malware Detection at the Edge with Lightweight LLMs: A Performance EvaluationabstractThe rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malware’s sophistication and adaptability, prompting a shift towards advanced methodologies like those leveraging Large Language Models (LLMs) for enhanced malware detection. However, deploying LLMs for malware detection directly at edge devices raises several challenges, including ensuring accuracy in constrained environments and addressing edge devices’ energy and computational limits. To tackle these challenges, this article proposes an architecture leveraging lightweight LLMs’ strengths while addressing limitations like reduced accuracy and insufficient computational power. To evaluate the effectiveness of the proposed lightweight LLM-based approach for edge computing, we perform an extensive experimental evaluation using several state-of-the-art lightweight LLMs. We test them with several publicly available datasets specifically designed for edge and IoT scenarios, and different edge nodes with varying computational power and characteristics. Christian Rondanini, Barbara Carminati, Elena Ferrari 0001, Ashish Kundu, Antonio Gaudiano |
ACM Trans. Internet Techn. | 2 |
| 2025 | Detecting Privacy Non-Compliance in Wearable Apps via Knowledge Graphs and LLMsabstractWearable devices are becoming increasingly popular in modern life, making significant contributions to human health monitoring. While security and privacy violations in standard apps have been extensively studied in many previous work, wearable apps have received comparatively little attention. This paper presents an automated framework that leverages Large Language Models (LLM) to identify privacy violations in Android wearable apps. The method evaluates both declared practices by extracting third-party services and shared data types from a Knowledge graph generated from the Manifest and Data Safety sections, and actual behaviors by analyzing sent-out network traffic. We evaluated the proposal on 711 popular companion apps and found that 67.5 % violate the declared data collection and sharing practices, with$\mathbf{4. 8 \%}$leaking data to undeclared third-party services. Tran Thanh Lam Nguyen, Barbara Carminati, Elena Ferrari 0001 |
WiMob | 2 |
| 2025 | A comprehensive survey on stegomalware detection in digital media, research challenges and future directionsabstractStegomalware is a malicious activity that employs steganography techniques to hide malicious code within innocent-looking files. The hidden code can then be executed to launch attacks on the victim’s computer or network. Unlike traditional malware, which performs malicious activities by executing its code, stegomalware is specifically designed to evade detection by hiding its malicious payload within seemingly harmless media files, making it difficult to detect using traditional anti-virus and anti-malware tools. To counter stegomalware, numerous steganalysis techniques have been developed for different digital media, such as images, audio, video, text, and networks. This survey presents a comprehensive and detailed overview of stegomalware, covering its background, techniques, modes of attacks, and evasion techniques in various digital media applications. It also provides notable case studies of stegomalware attacks and in-depth review of recent steganalysis approaches. In addition, the survey reviews widely used stegomalware tools and datasets. Finally, it discusses the limitations of state-of-the-art approaches and outlines related research trends. Laila Tul Badar, Barbara Carminati, Elena Ferrari 0001 |
Signal Process. | 2 |
| 2025 | ProMark: Ensuring Transparency and Privacy-Awareness in Proximity Marketing Advertising CampaignsabstractAdvertising campaigns are crucial in business development, but most marketing techniques target online purchases (e.g., Google Adsense) and rely on a centralized architecture to store and process the campaign's data and check its effectiveness. Recently, proximity marketing has become more popular thanks to the widespread use of smartphones. It exploits the short-range communication (e.g., Bluetooth) between smartphones and beacon devices to collect and send marketing information to customers. However, this might create privacy issues for customers due to the potential leakage of sensitive information (such as locations associated with time). In this paper, we propose ProMark, a privacy-aware blockchain-based platform to verify the effectiveness of proximity marketing campaigns by ensuring transparency, decentralization, and privacy in the measurement process. We implemented ProMark and carried out experiments that show that ProMark can be used in super-regional malls even during peak hours. Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | MetaLeak: Assessing Image Metadata Leakage in Android AppsabstractAlthough modern smartphone platforms emphasize user privacy protection by continually improving security mechanisms, vulnerabilities still exist, especially in the case of the Android operating system. The Android security mechanism almost delegates the entire responsibility of granting access permissions to apps to end users, who often are unaware of all the possible consequences of granting permission. Additionally, the loose protection mechanism regulating access to media files (images, videos, audio, etc.) can be exploited by attackers as a side-channel to gather sensitive data. This paper shows how sharing images containing sensitive metadata may result in an intentional or unintentional leakage of users' personal or confidential information. We designed MetaLeak, a system based on apps' hybrid analysis, to assess the identified risks. We used MetaLeak to analyze 5,000 popular apps and found that 21.9% of them sent at least one type of sensitive metadata over the internet. Moreover, for only 10.4% of the apps in our dataset, the app's actual behavior w.r.t. collecting GPS data is compliant with the developer's claims. Tran Thanh Lam Nguyen, Barbara Carminati, Elena Ferrari 0001 |
AICCSA | 2 |
| 2024 | Human Digital Twins: Efficient Privacy-Preserving Access Control Through Views Pre-materialisation
Giorgia Sirigu, Barbara Carminati, Elena Ferrari 0001 |
DBSec | 2 |
| 2024 | Protecting Privacy in Knowledge Graphs With Personalized AnonymizationabstractKnowledge graphs (KGs) are emerging data models allowing data providers to share data. This data sharing might bring new knowledge and collaborations, with evident benefits for providers. However, since KGs might contain sensitive information about users, it is of utmost importance to ensure KG anonymization before publishing. Recently, some proposals have addressed the problem of KGs' anonymization based on the$k$-anonymity principle. These techniques propose to anonymize the whole dataset with the same anonymization level. However, in a contest where data are collected from different users, it is crucial to consider also users' preferences on the anonymization level to adopt for their data. To cope with this requirement, this paper presents the Personalized$k$-Attribute Degree (p-$k$-ad) principle. It allows users to specify their anonymity levels (the$k$values) while preventing adversaries from re-identifying them with a confidence higher than$\frac{1}{k}$with their specified$k$. Moreover, we design the Personalized Cluster-Based Knowledge Graph Anonymization Algorithm (PCKGA) to generate anonymized KGs satisfying p-$k$-ad. We conduct experiments on four real-life datasets and show that PCKGA greatly improves the quality of anonymized KGs comparing to previous algorithms. Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Early-Stage Ransomware Detection Based on Pre-attack Internal API Calls
Filippo Coglio, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001 |
AINA (2) | 3 |
| 2023 | MalCon: A blockchain-based malware containment framework for Internet of ThingsabstractIoT devices have become a primary medium for malware (e.g., botnets) to launch Distributed Denial of Service (DDoS) attacks. Such malware exploit low-security measures in IoT devices to spread in networks and recruit new victims. Thus, there is a need for malware countermeasures that consider both the security and operability of the network. Indeed, some IoT devices might run critical processes that do not tolerate interruptions. This paper proposes MalCon, a blockchain-based malware containment framework for IoT. It aims to stop malware from spreading in a network by a set of containment strategies encoded into smart contracts to be executed by the infected devices. Moreover, MalCon provides a monitoring service that ensures trustworthy behavior in the network and reports to the system administrator any fraudulent activity of the monitored devices. MalCon was tested extensively with real-life malware and use cases. It quickly and drastically reduces the number of infected devices in a network, even in an extreme case of a fully connected network. Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 2 |
| 2022 | MalRec: A Blockchain-based Malware Recovery Framework for Internet of ThingsabstractIoT devices have been considered an attractive target for malware (e.g., botnets) due to their low computational resources and lack of security measures. The literature focuses on detecting malware, but less attention is given to recovery solutions. In addition, with the development of data processing regulations in different countries, a need for transparent recovery systems that can help organizations present their due diligence arises. This work proposes a blockchain-based backup policy enforcement framework for IoT where an organization can formalize backup policies and enforce them. We have run our solution under extensive tests that show that it can be deployed in real-life IoT environments, despite the limited computational resources of IoT devices. Ahmed Lekssays, Giorgia Sirigu, Barbara Carminati, Elena Ferrari 0001 |
ARES | 3 |
| 2022 | Enforcement of Laws and Privacy Preferences in Modern Computing SystemsabstractModern civilization is highly dependent on computing systems, touching all aspects of business, government, and individual life. At the same time, there has been an increase in laws and privacy preferences whose implementation and effectiveness depend on software. Whereas organizations and individuals have been expected to comply with laws and regulations, now computing systems must also be compliant and accountable. Computing systems need to be designed with privacy preferences and legal statutes in mind, and should be adaptable to change. Murat Kantarcioglu, Barbara Carminati, Sagar Samtani, Sudip Mittal, Maanak Gupta |
CODASPY | 2 |
| 2022 | A Blockchain-based Framework in Support of Privacy Preferences Enforcement for Scientific Workflows : (Invited Paper)abstractScientific workflows are today a vital tool for computational science, enabling the definition and execution of complex applications in heterogeneous and often distributed environments. A key characteristic of scientific workflow applications is that they often require the massive processing of an enormous amount of data that, in many cases, convey personal information. To allow an efficient and transparent privacy compliance check process, in this paper, we propose a blockchain-based solution coupled with an ad-hoc index structure that makes it possible an efficient compliance check for a massive amount of data. Federico Daidone, Barbara Carminati, Elena Ferrari 0001 |
ICWS | 2 |
| 2022 | PriApp-Install: Learning User Privacy Preferences on Mobile Apps' Installation
Ha Xuan Son, Barbara Carminati, Elena Ferrari 0001 |
ISPEC | 2 |
| 2022 | A Risk Estimation Mechanism for Android Apps based on Hybrid AnalysisabstractAbstract Mobile apps represent essential tools in our daily routines, supporting us in almost every task. However, this assistance might imply a high cost in terms of privacy. Indeed, mobile apps gather a massive amount of data about individuals (e.g., users’ profiles and habits) and their devices (e.g., locations), where not all are strictly needed for app execution. According to privacy laws, apps’ providers must inform end-users on adopted data usage practices (e.g., which data are collected and for which purpose). Unfortunately, understanding these practices is a complex task for average end-users. The result is that they install apps without understanding their privacy implications. To support users in making more privacy-aware decisions on app usage, we propose a risk estimation approach based on an analysis of the app’s code. This analysis adopts a hybrid strategy, exploiting static and dynamic code analyses. Static analysis aims at discovering which personal data an app is collecting to determine whether the target app is asking more than required. This gives the first estimation of the app’s risk level. In addition, we also perform a dynamic analysis of the target app’s code. This further analysis helps determining whether the collected personal data is consumed locally on the mobile device or sent out to external services. If this happens, the risk level has to be increased, as personal data are more exposed. To prove the proposal’s effectiveness, we run several experiments involving different groups of participants. The obtained accuracy results are promising and outperform those obtained with static analysis only. Ha Xuan Son, Barbara Carminati, Elena Ferrari 0001 |
Data Sci. Eng. | 2 |
| 2022 | Blockchain-Based Privacy Enforcement in the IoT DomainabstractThe Internet of Things (IoT) pervades our lives every day and has given end users the opportunity of accessing personalized and advanced services based on the analysis of the sensed data. However, IoT services are also characterized by new challenges related to security and privacy because end users often share sensitive data with different consumers without precise knowledge of how they will be managed and used. To cope with these issues, we propose a blockchain-based privacy enforcement framework where users can define how their data can be used and check if their will is respected without relying on a centralized manager. The preliminary tests we performed, simulating different scenarios, show the feasibility of our approach. Federico Daidone, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | LiMNet: Early-Stage Detection of IoT Botnets with Lightweight Memory Networks
Lodovico Giaretta, Ahmed Lekssays, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ESORICS (1) | 3 |
| 2021 | Privacy-Preserving Sequential Publishing of Knowledge GraphsabstractKnowledge graphs (KGs) are widely shared because they can model both users' attributes as well as their relationships. Unfortunately, adversaries can re-identify their victims in these KGs by using a rich background knowledge about not only the victims' attributes but also their relationships. A preliminary work to deal with this issue has been proposed in [1] which anonymizes both user attributes and relationships, but this is not enough. Indeed, adversaries can still re-identify target users if data providers publish new versions of their anonymized KGs. We remedy this problem by presenting the kw-Time-Varying Attribute Degree (kw-tad) principle that prevents adversaries from re-identifying any user appearing in w continuous anonymized KGs with a confidence higher than rac{1}{k}. Moreover, we introduce the Cluster-based Time-Varying Knowledge Graph Anonymization Algorithm to generate anonymized KGs satisfying kw-tad. Finally, we prove that even if data providers insert/re-insert/update/delete their users, the users are protected by kw-tad. Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
ICDE | 2 |
| 2021 | PAutoBotCatcher: A blockchain-based privacy-preserving botnet detector for Internet of Things
Ahmed Lekssays, Luca Landa, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 3 |
| 2021 | Privacy-Aware Personal Data Storage (P-PDS): Learning how to Protect User Privacy from External ApplicationsabstractRecently, Personal Data Storage (PDS) has inaugurated a substantial change to the way people can store and control their personal data, by moving from a service-centric to a user-centric model. PDS offers individuals the capability to keep their data in a unique logical repository, that can be connected and exploited by proper analytical tools, or shared with third parties under the control of end users. Up to now, most of the research on PDS has focused on how to enforce user privacy preferences and how to secure data when stored into the PDS. In contrast, in this paper we aim at designing a Privacy-aware Personal Data Storage (P-PDS), that is, a PDS able to automatically take privacy-aware decisions on third parties access requests in accordance with user preferences. The proposed P-PDS is based on preliminary results presented in [1] , where it has been demonstrated that semi-supervised learning can be successfully exploited to make a PDS able to automatically decide whether an access request has to be authorized or not. In this paper, we have deeply revised the learning process in order to have a more usable P-PDS, in terms of reduced effort for the training phase, as well as a more conservative approach w.r.t. users privacy, when handling conflicting access requests. We run several experiments on a realistic dataset exploiting a group of 360 evaluators. The obtained results show the effectiveness of the proposed approach. Bikash Chandra Singh, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Cluster-Based Anonymization of Knowledge Graphs
Anh-Tu Hoang, Barbara Carminati, Elena Ferrari 0001 |
ACNS (2) | 2 |
| 2018 | Detecting Spam Accounts on TwitterabstractSocial networks have become a popular way for internet surfers to interact with friends and family members, reading news, and also discuss events. Users spend more time on well-known social platforms (e.g., Facebook, Twitter, etc.) storing and sharing their personal information. This information together with the opportunity of contacting thousands of users attract the interest of malicious users. They exploit the implicit trust relationships between users in order to achieve their malicious aims, for example, create malicious links within the posts/tweets, spread fake news, send out unsolicited messages to legitimate users, etc. In this paper, we investigate the nature of spam users on Twitter with the goal to improve existing spam detection mechanisms. For detecting Twitter spammers, we make use of several new features, which are more effective and robust than existing used features (e.g., number of followings/followers, etc.). We evaluated the proposed set of features by exploiting very popular machine learning classification algorithms, namely k-Nearest Neighbor (k-NN), Decision Tree (DT), Naive Bayesian (NB), Random Forest (RF), Logistic Regression (LR), Support Vector Machine (SVM), and eXtreme Gradient Boosting (XG-Boost). The performance of these classifiers are evaluated and compared based on different evaluation metrics. We compared the performance of our proposed approach with four latest state of art approaches. The experimental results show that the proposed set of features gives better performance than existing state of art approaches. Md. Zulfikar Alom, Barbara Carminati, Elena Ferrari 0001 |
ASONAM | 2 |
| 2018 | Confidential Business Process Execution on BlockchainabstractOne of the main issues in service collaborations among business partners is the possible lack of trust among them. A promising approach to cope with this issue is leveraging on blockchain technology by encoding with smart contracts the business process workflow. This brings the benefits of trust decentralization, transparency, and accountability of the service composition process. However, data in the blockchain are public, implying thus serious consequences on confidentiality and privacy. Moreover, smart contracts can access data outside the blockchain only through Oracles, which might pose new confidentiality risks if no assumptions are made on their trustworthiness. For these reasons, in this paper, we are interested in investigating how to ensure data confidentiality during business process execution on blockchain even in the presence of an untrusted Oracle. Barbara Carminati, Christian Rondanini, Elena Ferrari 0001 |
ICWS | 1 |
| 2018 | Decentralizing privacy enforcement for Internet of Things smart objects
Gokhan Sagirlar, Barbara Carminati, Elena Ferrari 0001 |
Comput. Networks | 2 |
| 2018 | Risk Assessment in Social Networks Based on User Anomalous BehaviorsabstractAlthough the dramatic increase in Online Social Network (OSN) usage, there are still a lot of security and privacy concerns. In such a scenario, it would be very beneficial to have a mechanism able to assign a risk score to each OSN user. For this reason, in this paper, we propose a risk assessment based on the idea that the more a user behavior diverges from what it can be considered as a `normal behavior', the more it should be considered risky. In doing this, we have taken into account that OSN population is really heterogeneous in observed behaviors. As such, it is not possible to define a unique standard behavioral model that fits all OSN users' behaviors. However, we expect that similar people tend to follow similar rules with the results of similar behavioral models. For this reason, we propose a risk assessment approach organized into two phases: similar users are first grouped together, then, for each identified group, we build one or more models for normal behavior. The carried out experiments on a real Facebook dataset show that the proposed model outperforms a simplified behavioral-based risk assessment where behavioral models are built over the whole OSN population, without a group identification phase. Naeimeh Laleh, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2018 | Enhanced Audit Strategies for Collaborative and Accountable Data Sharing in Social NetworksabstractData sharing and access control management is one of the issues still hindering the development of decentralized online social networks (DOSNs), which are now gaining more research attention with the recent developments in P2P computing, such as the secure public ledger–based protocols (Blockchains) for monetary systems. In a previous work, we proposed an initial audit–based model for access control in DOSNs. In this article, we focus on enhancing the audit strategies and the privacy issues emerging from records kept for audit purposes. We propose enhanced audit and collaboration strategies, for which experimental results, on a real online social network graph with simulated sharing behavior, show an improvement in the detection rate of bad behavior of more than 50% compared to the basic model. We also provide an analysis of the related privacy issues and discuss possible privacy-preserving alternatives. Leila Bahri, Barbara Carminati, Elena Ferrari 0001, Andrea Bianco |
ACM Trans. Internet Techn. | 2 |
| 2018 | EditorialabstractI am very happy to report that TSC has gained an Impact Factor (IF) of 3.520 and the 5-year IF of 4.245, both of which represent significant increases from the previous years. This further speaks to the global reputation of the journal and the amazing work done by the past EICs, all the current and past EB members, and reviewers - all of whom have volunteered their precious time despite their very busy schedule to support and contribute to the growth of this journal. I hope to count on your continued engagement for the future growth of this journal. Over this past year, several esteemed EB members have completed their terms of service to TSC after serving for several years. On behalf of the Services Computing community and the TSC EAB, I would like to thank the following Associate Editors who retired from TSC EB in 2017 for their invaluable service and contributions to the journal. Overall, I am very proud of the success that TSC has achieved in 2017. This would not have been possible without the continued support of the authors, readers, reviewers, TSC EAB, TSC EB, and the staff of IEEE and IEEE Computer Society. I look forward to exploring ways to further enhance the reputation and impact of our journal. I would love to hear your suggestions and comments, and I hope to have your continued support. Paramvir Bahl, Barbara Carminati, James Caverlee, Ing-Ray Chen, Wynne Hsu, Toru Ishida 0001, Valérie Issarny, Surya Nepal, Indrakshi Ray, Kui Ren 0001, Shamik Sural, Mei-Ling Shyu |
IEEE Trans. Serv. Comput. | 2 |
| 2018 | Privacy in Web Service Transactions: A Tale of More than a Decade of WorkabstractThe web service computing paradigm has introduced great benefits to the growth of e-markets, both under the customer to business and the business to business models. The value capabilities allowed by the conception of web services, such as interoperability, efficiency, just-in-time integration, etc., have made them the most common way of doing business online. With the maturation of the web services underlying functional properties and facilitating standards, and with the proliferation of the amounts of data they use and they generate, researchers and practitioners have been dedicating considerable efforts to the related emerging privacy concerns. The literature contains number of research works on these privacy concerns, each addressing them from a different focal point. We have explored the available literature on web services privacy during transactions, to present, in this paper, a thorough survey of the most relevant published proposals. We identified 20 works that address privacy related problems in web services consumption. We categorize them based on the approach they take and we compare them based on a proposed evaluation framework, derived from the adopted techniques and addressed requirements. Leila Bahri, Barbara Carminati, Elena Ferrari 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2017 | SAMPAC: Socially-Aware collaborative Multi-Party Access ControlabstractAccording to the current design of content sharing services, such as Online Social Networks (OSNs), typically (i) the service provider has unrestricted access to the uploaded resources and (ii) only the user uploading the resource is allowed to define access control permissions over it. This results in a lack of control from other users that are associated, in some way, with that resource. To cope with these issues, in this paper, we propose a privacy-preserving system that allows users to upload their resources encrypted, and we design a collaborative multi-party access control model allowing all the users related to a resource to participate in the specification of the access control policy. Our model employs a threshold-based secret sharing scheme, and by exploiting users' social relationships, sets the trusted friends of the associated users responsible to partially enforce the collective policy. Through replication of the secret shares and delegation of the access control enforcement role, our model ensures that resources are timely available when requested. Finally, our experiments demonstrate that the performance overhead of our model is minimal and that it does not significantly affect user experience. Panagiotis Ilia, Barbara Carminati, Elena Ferrari 0001, Paraskevi Fragopoulou, Sotiris Ioannidis |
CODASPY | 2 |
| 2017 | Learning Privacy Habits of PDS OwnersabstractThe concept of Personal Data Storage (PDS) has recently emerged as an alternative and innovative way of managing personal data w.r.t. the service-centric one commonly used today. The PDS offers a unique logical repository, allowing individuals to collect, store, and give access to their data to third parties. The research on PDS has so far mainly focused on the enforcement mechanisms, that is, on how user privacy preferences can be enforced. In contrast, the fundamental issue of preference specification has been so far not deeply investigated. In this paper, we do a step in this direction by proposing different learning algorithms that allow a fine-grained learning of the privacy aptitudes of PDS owners. The learned models are then used to answer third party access requests. The extensive experiments we have performed show the effectiveness of the proposed approach. Bikash Chandra Singh, Barbara Carminati, Elena Ferrari 0001 |
ICDCS | 2 |
| 2016 | CrowdSelect: Increasing Accuracy of Crowdsourcing Tasks through Behavior Prediction and User SelectionabstractCrowdsourcing allows many people to complete tasks of various difficulty with minimal recruitment and administration costs. However, the lack of participant accountability may entice people to complete as many tasks as possible without fully engaging in them, jeopardizing the quality of responses. In this paper, we present a dynamic and time efficient solution to the task assignment problem in crowdsourcing platforms. Our proposed approach, CrowdSelect, offers a theoretically proven algorithm to assign workers to tasks in a cost efficient manner, while ensuring high accuracy of the overall task. In contrast to existing works, our approach makes minimal assumptions on the probability of error for workers, and completely removes the assumptions that such probability is known apriori and that it remains consistent over time. Through experiments over real Amazon Mechanical Turk traces and synthetic data, we find that CrowdSelect has a significant gain in term of accuracy compared to state-of-the-art algorithms, and can provide a 17.5\% gain in answers' accuracy compared to previous methods, even when there are over 50\% malicious workers. Chenxi Qiu, Anna Cinzia Squicciarini, Barbara Carminati, James Caverlee, Dev Rishi Khare |
CIKM | 3 |
| 2016 | Beat the DIVa - decentralized identity validation for online social networksabstractFake accounts in online social networks (OSNs) have known considerable sophistication and are now attempting to gain network trust by infiltrating within honest communities. Honest users have limited perspective on the truthfulness of new online identities requesting their friendship. This facilitates the task of fake accounts in deceiving honest users to befriend them. To address this, we have proposed a model that learns hidden correlations between profile attributes within OSN communities, and exploits them to assist users in estimating the trustworthiness of new profiles. To demonstrate our method, we suggest, in this demo, a game application through which players try to cheat the system and convince nodes in a simulated OSN to befriend them. The game deploys different strategies to challenge the players and to reach the objectives of the demo. These objectives are to make participants aware of how fake accounts can infiltrate within their OSN communities, to demonstrate how our suggested method could aid in mitigating this threat, and to eventually strengthen our model based on the data collected from the moves of the players. Leila Bahri, Amira Soliman 0001, Jacopo Squillaci, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ICDE | 4 |
| 2016 | A Language and an Inference Engine for Twitter Filtering RulesabstractWe consider the problem of the filtering of Twitter posts, that is, the hiding of those posts which the user prefers not to visualize on his/her timeline. We define a language for specifying filtering policies suitable for Twitter posts. The language allows each user to decide which posts to filter out based on his/her sensibility and preferences. Since average users may not have the skills necessary to translate their filtering needs into a set of rules, we also propose a method for inferring a policy automatically, based solely on examples of the desired filtering behavior. The method is based on an evolutionary approach driven by a multi-objective optimization scheme. We assess our proposal experimentally on a real Twitter dataset and the results are highly promising. Alberto Bartoli, Barbara Carminati, Elena Ferrari 0001, Eric Medvet |
WI | 2 |
| 2016 | LAMP - Label-Based Access-Control for More Privacy in Online Social Networks
Leila Bahri, Barbara Carminati, Elena Ferrari 0001, William Lucia |
WISTP | 2 |
| 2016 | Trustworthy and effective person-to-person payments over multi-hop MANETs
Barbara Carminati, Elena Ferrari 0001, Ngoc Hong Tran |
J. Netw. Comput. Appl. | 1 |
| 2016 | Detection of Unspecified Emergencies for Controlled Information SharingabstractDuring emergency situations one of the key requirements to handle the crisis is information sharing among organizations involved in the emergency management. When emergency situations are well known, it is possible to specify a priori these situations and to plan the information sharing needs in advance. However, there are many situations where it is not possible to describe these emergencies and their information sharing requirements beforehand. Therefore, in this paper, we present a framework able to deal with both specified and unspecified emergencies. The idea is to detect unspecified emergencies and related information sharing needs through denied access request analysis, anomaly detection techniques, and analysis of the history of permitted access requests. Besides presenting the techniques, the paper also presents experiments to verify their effectiveness. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | COIP - Continuous, Operable, Impartial, and Privacy-Aware Identity Validity Estimation for OSN ProfilesabstractIdentity validation of Online Social Networks’ (OSNs’) peers is a critical concern to the insurance of safe and secure online socializing environments. Starting from the vision of empowering users to determine the validity of OSN identities, we suggest a framework to estimate the trustworthiness of online social profiles based only on the information they contain. Our framework is based on learning identity correlations between profile attributes in an OSN community and on collecting ratings from OSN community members to evaluate the trustworthiness of target profiles. Our system guarantees utility, user anonymity, impartiality in rating, and operability within the dynamics and continuous evolution of OSNs. In this article, we detail the system design, and we prove its correctness against these claimed quality properties. Moreover, we test its effectiveness, feasibility, and efficiency through experimentation on real-world datasets from Facebook and Google+, in addition to using the Adults UCI dataset. Leila Bahri, Barbara Carminati, Elena Ferrari 0001 |
ACM Trans. Web | 2 |
| 2015 | DIVa: Decentralized Identity Validation for Social NetworksabstractOnline Social Networks exploit a lightweight process to identify their users so as to facilitate their fast adoption. However, such convenience comes at the price of making legitimate users subject to different threats created by fake accounts. Therefore, there is a crucial need to empower users with tools helping them in assigning a level of trust to whomever they interact with. To cope with this issue, in this paper we introduce a novel model, DIVa, that leverages on mining techniques to find correlations among user profile attributes. These correlations are discovered not from user population as a whole, but from individual communities, where the correlations are more pronounced. DIVa exploits a decentralized learning approach and ensures privacy preservation as each node in the OSN independently processes its local data and is required to know only its direct neighbors. Extensive experiments using real-world OSN datasets show that DIVa is able to extract fine-grained community-aware correlations among profile attributes with average improvements up to 50% than the global approach. Amira Soliman 0001, Leila Bahri, Barbara Carminati, Elena Ferrari 0001, Sarunas Girdzijauskas |
ASONAM | 3 |
| 2015 | Evolutionary Inference of Attribute-Based Access Control Policies
Eric Medvet, Alberto Bartoli, Barbara Carminati, Elena Ferrari 0001 |
EMO (1) | 3 |
| 2015 | A Privacy-Preserving Framework for Constrained Choreographed Service CompositionabstractOne of the major goals of Web services is to make easier their composition to form more complex services, modeled as workflows. A key role in the Web services composition is the selection of a proper service for each activity in the workflow. In general, this requires the exchange of sensitive information of users, requiring the composition, as well as of involved service providers. So far this problem has been investigated in the setting of orchestrated service composition, under the assumption of the presence of a broker coordinating the composition. However, a promising alternative approach is the one of choreography, where each service involved in the service composition has to locally manage service selection and invocation. In this paper, we propose a framework to enforce user and provider requirements in the scenario of service choreography in a privacy-preserving way, that is, without the releasing of any private information of users and providers. To achieve this result we make use of different privacy-preserving protocols. As it will be shown in the paper, the proposed solution does not implies relevant overhead. Barbara Carminati, Elena Ferrari 0001, Ngoc Hong Tran |
ICWS | 1 |
| 2014 | Relationship-based information sharing in cloud-based decentralized social networksabstractCommercial OSNs have started to provide users with the ability to set their privacy settings for a more controlled information sharing. However, these settings do not prevent the social network manager to perform marketing research on user personal data, aiming, as example, at offering a personalized advertising to users. To cope with these requirements Decentralized Social Networks (DSNs) are emerged as a possible solution for moving users' personal data out from OSN realms. Unfortunately, it has been shown that DSNs have some limitations, in terms of usability and social features they offer. To overcome this problem, in this paper we extend the DSN framework so that users' data (e.g., resources and relationships) are securely stored in a public cloud data storage and shared according to relationship-based rules defined by owners, by at the same time supporting a privacy-preserving path finding. To this end, we make use of encryption techniques and we devise a new collaborative anonymization process. In the paper, besides presenting all the components of our framework, we analyze its security and present experiments showing the feasibility of the developed techniques. Davide Alberto Albertini, Barbara Carminati |
CODASPY | 2 |
| 2014 | Community-Based Identity Validation on Online Social NetworksabstractIdentity management in online social networks (OSNs) is a challenging, yet important requirement for effective privacy protection and trust management. Literature offers several proposals addressing issues related to identity breaches and/or identity related attacks on OSNs, but only a few aim at giving means to judge users' reliability in terms of trustworthiness of their claimed identities. In this paper, we propose an identity validation process that relies on OSN community feedback to assign to OSN users identity trustworthiness levels. For this purpose, we define a community based supervised learning process to detect the set of attributes in a user profile for which it is expected to see a correlation among their values (e.g., job and salary). Once these correlated attribute sets are identified, the profile of a target user is judged by a selected group of raters to estimate her identity trustworthiness level. We demonstrate the effectiveness of our proposal through experimentation under two different scenarios and using real data. The experiments' results under the two scenarios demonstrate the effectiveness and meaningfulness of our proposal. Leila Bahri, Barbara Carminati, Elena Ferrari 0001 |
ICDCS | 2 |
| 2014 | Secure Web Service Composition with Untrusted BrokerabstractComposite web services are usually coordinated according to a workflow, composed by several activities, each of which carried out by a service. A way to coordinate this cooperation is orchestration, which implies that the workflow underlying the composite web service is processed by a broker hosting a workflow engine (e.g., BPEL engine). According to the orchestration paradigm, the broker coordinates the invocation of services involved in the composition by passing the needed parameters. In general, all previous proposals for the service orchestration model consider the broker as a trusted entity. As such, they never payed attention to the fact that the broker is able to access several pieces of sensitive data. We believe there is the need to protect them against improper access and usage from partner services as well as the broker. To cope with these issues, in this paper, we propose a protocol based on a selective encryption able to ensure that both the broker and service partners can access only the information needed to fulfill their activities. Barbara Carminati, Elena Ferrari 0001, Ngoc Hong Tran |
ICWS | 1 |
| 2014 | Editorial
Lakshmish Ramaswamy, Barbara Carminati, Lujo Bauer, Dongwan Shin, James B. D. Joshi, Calton Pu, Dimitris Gritzalis |
Comput. Secur. | 2 |
| 2014 | Preface
Barbara Carminati, Lakshmish Ramaswamy, Anna Cinzia Squicciarini, James B. D. Joshi, Calton Pu |
Int. J. Cooperative Inf. Syst. | 1 |
| 2014 | Editorial: Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom 2012)
Lakshmish Ramaswamy, Barbara Carminati, James B. D. Joshi, Calton Pu |
Mob. Networks Appl. | 2 |
| 2013 | Privacy aware service selection of composite web services invited paperabstractWeb service selection involves finding services from a possibly huge database of similar services. Hence, the challenges involved in finding a suitable service include large time consumption, and difficulty of finding a perfect match according to the user specified search keywords. In addition Anna Cinzia Squicciarini, Barbara Carminati, Sushama Karumanchi |
CollaborateCom | 2 |
| 2013 | Controlled information sharing for unspecified emergenciesabstractDuring emergency situations a key requirement is information sharing. If emergencies are known a-priori, it is possible to specify them using emergency policies, modeling the extra sharing needs usually arising during emergencies. However, there are many situations where emergencies can be unspecified and yet they require a timely information sharing. Therefore, in this paper, we present an extended model which is able to deal with such emergencies. The idea is to open the system to some controlled violations, i.e., those denied access requests that signal the occurrence of an unspecified emergency. We have defined measures to determine whether a denied access request represents an information need for an unspecified emergency or the risk of an attempted abuse, and we have carried out experiments to verify the effectiveness of the proposed measures comparing them with a human-based evaluation. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
CRiSIS | 1 |
| 2013 | SHARE: Secure information sharing framework for emergency managementabstract9/11, Katrina, Fukushima and other recent emergencies demonstrate the need for effective information sharing across government agencies as well as non-governmental and private organizations to assess emergency situations, and generate proper response plans. In this demo, we present a system to enforce timely and controlled information sharing in emergency situations. The framework is able to detect emergencies, enforce temporary access control policies and obligations to be activated during emergencies, simulate emergency situations for demonstrational purposes and show statistical results related to emergency activation/deactivation and consequent access control policies triggering. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
ICDE | 1 |
| 2013 | Policy-Compliant Search Query Routing for Web Service Discovery in Peer to Peer NetworksabstractWeb services are increasingly hosted on peer to peer networks, to facilitate resource sharing and cooperation. In these settings, each peer hosts a set of services which can be invoked by other peers of the network through a service query. In a pure peer to peer network, it might not be possible to maintain directory for publishing the services, rather, the peers need to search for the required service through query forwarding in the network. For such non-directory based peer to peer networks, in this paper, we introduce an efficient and fully decentralized policy-compliant search query routing method for service discovery. Our main goal is to protect the search query from traversing unwanted peers in the network, while achieving service discovery. To this end, we design and develop a policy-driven approach that allows distributed searches through service queries taking into account any security, routing or other functional criteria a peer may have with respect to routing a query. We have developed a prototype of the query protection and search protocol, and tested it on large networks. Our tests demonstrate accuracy and efficient execution times. Sushama Karumanchi, Anna Cinzia Squicciarini, Barbara Carminati |
ICWS | 3 |
| 2013 | A System for Timely and Controlled Information Sharing in Emergency SituationsabstractDuring natural disasters or emergency situations, an essential requirement for an effective emergency management is the information sharing. In this paper, we present an access control model to enforce controlled information sharing in emergency situations. An in-depth analysis of the model is discussed throughout the paper, and administration policies are introduced to enhance the model flexibility during emergencies. Moreover, a prototype implementation and experiments results are provided showing the efficiency and scalability of the system. Barbara Carminati, Elena Ferrari 0001, Michele Guglielmi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2013 | A System to Filter Unwanted Messages from OSN User WallsabstractOne fundamental issue in today's Online Social Networks (OSNs) is to give users the ability to control the messages posted on their own private space to avoid that unwanted content is displayed. Up to now, OSNs provide little support to this requirement. To fill the gap, in this paper, we propose a system allowing OSN users to have a direct control on the messages posted on their walls. This is achieved through a flexible rule-based system, that allows users to customize the filtering criteria to be applied to their walls, and a Machine Learning-based soft classifier automatically labeling messages in support of content-based filtering. Marco Vanetti, Elisabetta Binaghi, Elena Ferrari 0001, Barbara Carminati, Moreno Carullo |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2012 | Preface
Barbara Carminati, Lakshmish Ramaswamy, Calton Pu, James B. D. Joshi |
CollaborateCom | 1 |
| 2012 | Privacy in Social Networks: How Risky is Your Social Graph?abstractSeveral efforts have been made for more privacy aware Online Social Networks (OSNs) to protect personal data against various privacy threats. However, despite the relevance of these proposals, we believe there is still the lack of a conceptual model on top of which privacy tools have to be designed. Central to this model should be the concept of risk. Therefore, in this paper, we propose a risk measure for OSNs. The aim is to associate a risk level with social network users in order to provide other users with a measure of how much it might be risky, in terms of disclosure of private information, to have interactions with them. We compute risk levels based on similarity and benefit measures, by also taking into account the user risk attitudes. In particular, we adopt an active learning approach for risk estimation, where user risk attitude is learned from few required user interactions. The risk estimation process discussed in this paper has been developed into a Facebook application and tested on real data. The experiments show the effectiveness of our proposal. Cuneyt Gurcan Akcora, Barbara Carminati, Elena Ferrari 0001 |
ICDE | 2 |
| 2012 | Trust and Share: Trusted Information Sharing in Online Social NetworksabstractAt the beginning of Web 2.0 era, Online Social Networks (OSNs) appeared as just another phenomenon among wikis, blogs, video sharing, and so on. However, they soon became one of the biggest revolution of the Internet era. Statistics confirm the continuing rise in the importance of social networking sites in terms of number of users (e.g., Facebook reaches 750 millions users, Twitter 200 millions, LinkedIn 100 millions), time spent in social networking sites, and amount of data flowing (e.g., Facebook users interact with about 900 million piece of data in terms of pages, groups, events and community pages). This successful trend lets OSNs to be one of the most promising paradigms for information sharing on the Web. Barbara Carminati, Elena Ferrari 0001, Jacopo Girardi |
ICDE | 1 |
| 2012 | Risks of Friendships on Social NetworksabstractIn this paper, we explore the risks of friends in social networks caused by their friendship patterns, by using real life social network data and starting from a previously defined risk model. Particularly, we observe that risks of friendships can be mined by analyzing users' attitude towards friends of friends. This allows us to give new insights into friendship and risk dynamics on social networks. Cuneyt Gurcan Akcora, Barbara Carminati, Elena Ferrari 0001 |
ICDM | 2 |
| 2012 | A multi-layer framework for personalized social tag-based applications
Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
Data Knowl. Eng. | 1 |
| 2011 | A probability-based approach to modeling the risk of unauthorized propagation of information in on-line social networksabstractThe unauthorized propagation of information is an important problem in the Internet, especially because of the increasing popularity of On-line Social Networks. To address this issue, many access control mechanisms have been proposed so far, but there is still a lack of techniques to evaluate the risk of unauthorized flow of information within social networks. This paper introduces a probability-based approach to modeling the likelihood that information propagates from one social network user to users who are not authorized to access it. The approach is demonstrated via an example, to show how it can be applied in practical cases. Barbara Carminati, Elena Ferrari 0001, Sandro Morasca, Davide Taibi 0001 |
CODASPY | 1 |
| 2011 | Collaborative access control in on-line social networksabstractTopology-based access control is today a de-facto standard for protecting resources in On-line Social Networks (OSNs) both within the research community and commercial OSNs. According to this paradigm, authorization constraints specify the relationships (and possibly their depth and trust level) tha Barbara Carminati, Elena Ferrari 0001 |
CollaborateCom | 1 |
| 2011 | P3D - Privacy-Preserving Path Discovery in Decentralized Online Social NetworksabstractOne of the key service of social networks is path discovery, in that release of a resource or delivering of a service is usually constrained by the existence of a path with given characteristics in the social network graph. One fundamental issue is that path discovery should preserve relationship privacy. In this paper, we address this issue by proposing a Privacy-Preserving Path Discovery protocol, called P3D. Relevant features of P3D are that: (1) it computes only aggregate information on the discovered paths, whereas details on single relationships are not revealed to anyone, (2) it is designed for a decentralized social network. Moreover, P3D is designed such to reduce the drawbacks that offline nodes may create to path discovery. In the paper, besides giving the details of the protocol, we provide an extensive performance study. We also present the security analysis of P3D, showing its robustness against the main security threats. Mingqiang Xue, Barbara Carminati, Elena Ferrari 0001 |
COMPSAC | 2 |
| 2011 | A Privacy-Preserving Approach for Web Service Selection and ProvisioningabstractThe growing success of WS-related technologies has resulted in a large number of providers, which implement services of varying degree of sophistication and complexity. While on the one hand the availability of a wide array of services has created a competitive and flexible market that suits well the needs of different type of users, on the other hand, it requires them to select among possibly hundreds of similar services. As such, Web service selection plays a crucial role in Web service life-cycle. Here, several application-dependent requirements might constrain the selection of the best service. In this paper, we study the privacy implications caused by the exchange of large amount of potentially sensitive data required by optimized strategies for service-selection. In particular, we propose a comprehensive framework to uniformly protect users' and service providers' privacy needs, at the time of service selection. We define a solution that allows matching of the search criteria against the Web services attributes in a private fashion such that both criteria and service attributes are kept private during the matching. Further, we propose an approach to protect service provisioning rules from unwanted disclosure, both from the user and the service provider's perspective. Our experimental evaluation and complexity analysis demonstrate that our algorithms are efficient. Anna Cinzia Squicciarini, Barbara Carminati, Sushama Karumanchi |
ICWS | 2 |
| 2011 | Semantic web-based social network access control
Barbara Carminati, Elena Ferrari 0001, Raymond Heatherly, Murat Kantarcioglu, Bhavani Thuraisingham |
Comput. Secur. | 1 |
| 2011 | CASTLE: Continuously Anonymizing Data StreamsabstractMost of the existing privacy-preserving techniques, such as k-anonymity methods, are designed for static data sets. As such, they cannot be applied to streaming data which are continuous, transient, and usually unbounded. Moreover, in streaming applications, there is a need to offer strong guarantees on the maximum allowed delay between incoming data and the corresponding anonymized output. To cope with these requirements, in this paper, we present Continuously Anonymizing STreaming data via adaptive cLustEring (CASTLE), a cluster-based scheme that anonymizes data streams on-the-fly and, at the same time, ensures the freshness of the anonymized data by satisfying specified delay constraints. We further show how CASTLE can be easily extended to handle ℓ-diversity. Our extensive performance study shows that CASTLE is efficient and effective w.r.t. the quality of the output data. Jianneng Cao, Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | Guest Editorial SACMAT 2009 and 2010abstractNo abstract available. James B. D. Joshi, Barbara Carminati |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2010 | A framework to enforce access control over data streamsabstractAlthough access control is currently a key component of any computational system, it is only recently that mechanisms to guard against unauthorized access to streaming data have started to be investigated. To cope with this lack, in this article, we propose a general framework to protect streaming data, which is, as much as possible, independent from the target stream engine. Differently from RDBMSs, up to now a standard query language for data streams has not yet emerged and this makes the development of a general solution to access control enforcement more difficult. The framework we propose in this article is based on an expressive role-based access control model proposed by us. It exploits a query rewriting mechanism, which rewrites user queries in such a way that they do not return tuples/attributes that should not be accessed according to the specified access control policies. Furthermore, the framework contains a deployment module able to translate the rewritten query in such a way that it can be executed by different stream engines, therefore, overcoming the lack of standardization. In the article, besides presenting all the components of our framework, we prove the correctness and completeness of the query rewriting algorithm, and we present some experiments that show the feasibility of the developed techniques. Barbara Carminati, Elena Ferrari 0001, Jianneng Cao, Kian-Lee Tan |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2009 | Compatibility-driven and adaptable service compositionabstractServices participating in the composition are usually co-ordinated according to a workflow, composed by several activities, each of which carried out by a service. The binding of services to workflow activities may be affected by several parameters (e.g., QoS, price, reputation, etc.). In this paper, we propose a service binding driven by a further important requirement, that is, the incompatibilities among services participating into the composition. To achieve a compatibility-driven composition we propose a solution where services assignment is configured directly by the engine coordinating the composite service. Moreover, the composition is generated such to implement a failure recovery strategy, that is, in case of some service failure the engine dynamically replaces the unavailable service. Barbara Carminati, Chihung Chi, Elena Ferrari 0001, Lianghuan Yu |
APSCC | 1 |
| 2009 | Enforcing relationships privacy through collaborative access control in web-based Social NetworksabstractWeb-based social networks (WBSNs) are today one of the hugest data source available on the Web and therefore data protection has become an urgent need. This has resulted in the proposals of some access control models for social networks. Quite all the models proposed so far enforce a relationship-ba Barbara Carminati, Elena Ferrari 0001 |
CollaborateCom | 1 |
| 2009 | The Quality Social Network: A collaborative environment for personalizing Web accessabstractIn this paper, we present a collaborative social networking environment, referred to as quality social network (QSN), which enhances the social tagging paradigm by using it as a basis to evaluate the quality of Web resources, on the basis of the user preferences specified by each QSN member. Such fe Andrea Perego, Barbara Carminati, Elena Ferrari 0001 |
CollaborateCom | 2 |
| 2009 | ACStream: Enforcing Access Control over Data StreamsabstractIn this demo proposal, we illustrate ACStream, a system built on top of Stream Base, to specify and enforce access control policies over data streams. ACStream supports a very flexible role-based access control model specifically designed to protect against unauthorized access to streaming data. The core component of ACStream is a query rewriting mechanism that, by exploiting a set of secure operators proposed by us in, rewrites a user query in such a way that it does not violate the specified access control policies during its execution. The demo will show how policies modelling a variety of access control requirements can be easily specified and enforced using ACStream. Jianneng Cao, Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
ICDE | 2 |
| 2009 | A semantic web based framework for social network access controlabstractThe existence of on-line social networks that include person specific information creates interesting opportunities for various applications ranging from marketing to community organization. On the other hand, security and privacy concerns need to be addressed for creating such applications. Improving social network access control systems appears as the first step toward addressing the existing security and privacy concerns related to on-line social networks. To address some of the current limitations, we propose an extensible fine grained access control model based on semantic web tools. In addition, we propose authorization, admin and filtering policies that depend on trust relationships among various users, and are modeled using OWL and SWRL. Besides describing the model, we present the architecture of the framework in its support. Barbara Carminati, Elena Ferrari 0001, Raymond Heatherly, Murat Kantarcioglu, Bhavani Thuraisingham |
SACMAT | 1 |
| 2009 | Enforcing access control in Web-based social networksabstractIn this article, we propose an access control mechanism for Web-based social networks, which adopts a rule-based approach for specifying access policies on the resources owned by network participants, and where authorized users are denoted in terms of the type, depth, and trust level of the relationships existing between nodes in the network. Different from traditional access control systems, our mechanism makes use of a semidecentralized architecture, where access control enforcement is carried out client-side. Access to a resource is granted when the requestor is able to demonstrate being authorized to do that by providing a proof. In the article, besides illustrating the main notions on which our access control model relies, we present all the protocols underlying our system and a performance study of the implemented prototype. Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2008 | Combining Social Networks and Semantic Web Technologies for Personalizing Web Access
Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
CollaborateCom | 1 |
| 2008 | Privacy-Aware Collaborative Access Control in Web-Based Social Networks
Barbara Carminati, Elena Ferrari 0001 |
DBSec | 1 |
| 2008 | CASTLE: A delay-constrained scheme for ks-anonymizing data streamsabstractMost of existing privacy preserving techniques, such as k-anonymity methods, are designed for static data sets. As such, they cannot be applied to streaming data which are continuous, transient and usually unbounded. Moreover, in streaming applications, there is a need to offer strong guarantees on the maximum allowed delay between an incoming data and its anonymized output. To cope with these requirements, in this paper, we present CASTLE (Continuously Anonymizing STreaming data via adaptive cLustEring), a cluster-based scheme that anonymizes data streams on-the-fly and, at the same time, ensures the freshness of the anonymized data by satisfying specified delay constraints. We further show how CASTLE can be easily extended to handle l-diversity [1]. Our extensive performance study shows that CASTLE is efficient and effective. Jianneng Cao, Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
ICDE | 2 |
| 2008 | A Decentralized Security Framework for Web-Based Social NetworksabstractThe wide diffusion and usage of social networking Web sites in the last years have made publicly available a huge amount of possible sensitive information, which can be used by third-parties with purposes different from the ones of the owners of such information. Currently, this issue has been addressed by enforcing into Web-based Social Networks (WBSNs) very simple protection mechanisms, or by using anonymization techniques, thanks to which it is possible to hide the identity of WBSN members while performing analysis on social network data. However, we believe that further solutions are needed, to allow WBSN members themselves to decide who can access their personal information and resources. To cope with this issue, in this article we illustrate a decentralized security framework for WBSNs, which provide both access control and privacy protection mechanisms. In our system, WBSN members can denote who is authorized to access the resources they publish and the relationships they participate in, in terms of the type, depth, and trust level of the relationships existing between members of a WBSN. Cryptographic techniques are then used to provide a controlled sharing of resources while preserving relationship privacy. Barbara Carminati, Elena Ferrari 0001, Andrea Perego |
Int. J. Inf. Secur. Priv. | 1 |
| 2007 | Specifying Access Control Policies on Data Streams
Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
DASFAA | 1 |
| 2007 | Towards Secure Execution Orders for CompositeWeb ServicesabstractRecently, there has been a growing interest in web service composition and the related security issues. In this paper, we propose a framework for the decentralized execution of composite web services capable to ensure the correctness as well as the security of the execution. Our framework relies on a data structure, called container, which is passed among the web services participating in the composition. The container is encrypted and authenticated in such a way to ensure the correctness of the execution flow as well as a set of relevant security requirements. Joachim Biskup, Barbara Carminati, Elena Ferrari 0001, Sandra Wortmann |
ICWS | 2 |
| 2007 | Enforcing access control over data streamsabstractAccess control is an important component of any computational system. However, it is only recently that mechanisms to guard against unauthorized access for streaming data have been proposed. In this paper, we study how to enforce the role-based access control model proposed by us in [5]. We design a set of novel secure operators, that basically filter out tuples/attributes from results of the corresponding (non-secure) operators that are not accessible according to the specified access control policies. We further develop an access control mechanism to enforce the access control policies based on these operators. We show that our method is secure according to the specified policies. Barbara Carminati, Elena Ferrari 0001, Kian-Lee Tan |
SACMAT | 1 |
| 2006 | Security Conscious Web Service CompositionabstractA Web service is a software system designed to support interoperable application-to-application interactions over the Internet. Web services are based on a set of XML standards, such as Web Services Description Language (WSDL), Simple Object Access Protocol (SOAP) and Universal Description, Discovery and Integration (UDDI). Recently, there has been a growing interest in Web service composition, and some languages (e.g., WSBPEL, BPML) for modeling the composition have been proposed. In this paper, we focus on security constraints of Web service composition, which have not been deeply investigated so far. We propose a method for modeling security constraints and a brokered architecture to build composite Web services according to the specified security constraints. Barbara Carminati, Elena Ferrari 0001, Patrick C. K. Hung |
ICWS | 1 |
| 2005 | Securing XML data in third-party distribution systemsabstractWeb-based third-party architectures for data publishing are today receiving growing attention, due to their scalability and the ability to efficiently manage large numbers of users and great amounts of data. A third-party architecture relies on a distinction between the Owner and the Publisher of information. The Owner is the producer of information, whereas Publisher provides data management services and query processing functions for (a portion of) the Owner's information. In such architecture, there are important security concerns especially if we do not want to make any assumption on the trustworthy of the Publishers. Although approaches have been proposed [4, 5] providing partial solutions to this problem, no comprehensive framework has been so far developed able to support all the most important security properties in the presence of an untrusted Publisher. In this paper, we develop an XML-based solution to such problem, which makes use of non-conventional digital signature techniques and queries over encrypted data. Barbara Carminati, Elena Ferrari 0001, Elisa Bertino |
CIKM | 1 |
| 2005 | Assuring Security Properties in Third-party ArchitecturesabstractWeb-based third-party architectures for data publishing are today receiving growing attention, due to their scalability and the ability of efficiently managing large numbers of users and great amounts of data. In such architecture security is a primary challenge. Main security properties that should be considered are: confidentiality, integrity, and authenticity. Additionally to these traditional security requirements, we are interested in a further security property, that is, completeness. By completeness we mean that the user receiving a portion of data can verify whether he/she has received all the information is allowed to see according to the specified access control policies. In this paper, we propose a comprehensive framework for a secure third party distribution of XML data. In particular, the framework is able to enforce all the above-mentioned properties, by exploiting encryption and non-conventional signature techniques. Barbara Carminati, Elena Ferrari 0001, Elisa Bertino |
ICDE | 1 |
| 2005 | AC-XML documents: improving the performance of a web access control moduleabstractProtecting information over the Web is today becoming a primary need. Although many access control models have been so far proposed to address the specific protection requirements of the web environment, no comparable amount of work has been done for finding efficient techniques for performing access control. We believe that the availability of techniques for speeding-up access control is a key issue to make an access control model widely acceptable. This is particularly crucial in an environment such as the web, characterized by thousands of users and thousands of documents. For these reasons, in this paper we propose a technique for speeding-up access control, which can be applied to credential-based access control models. We propose a data structure that keeps track of the policies that apply to the various portions of a data source, and which does not require the scanning of the policy base for performing access control. In the paper, besides giving the algorithms for building such data structure and for performing access control, we present a complexity analysis of the proposed approach, which demonstrates the benefits with traditional methods. Barbara Carminati, Elena Ferrari 0001 |
SACMAT | 1 |
| 2004 | Towards Standardized Web Services Privacy TechnologiesabstractA Web service is defined as an autonomous unit of application logic that provides either some business functionality or information to other applications through an Internet connection. Web services are based on a set of XML standards such as universal description, discovery and integration (UDDI), Web services description language (WSDL), and simple object access protocol (SOAP). Recently there are increasing demands and discussions about Web services privacy technologies in the industry and research community. In general, privacy policies describe an organization's data practices what information they collect from individuals (e.g., consumers) and what (e.g., purposes) they do with it. To enable privacy protection for Web service consumers across multiple domains and services, the World Wide Web Consortium (W3C) published a document called "Web services architecture (WSA) requirements" that defines some specific privacy requirements for Web services as a future research topic. At this moment, there is still no standardized Web services privacy technology. This paper briefly overviews the research issues of Web services privacy technologies. Patrick C. K. Hung, Elena Ferrari 0001, Barbara Carminati |
ICWS | 3 |
| 2004 | Access control for XML documents and data
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
Inf. Secur. Tech. Rep. | 2 |
| 2004 | Selective and Authentic Third-Party Distribution of XML DocumentsabstractThird-party architectures for data publishing over the Internet today are receiving growing attention, due to their scalability properties and to the ability of efficiently managing large number of subjects and great amount of data. In a third-party architecture, there is a distinction between the Owner and the Publisher of information. The Owner is the producer of information, whereas Publishers are responsible for managing (a portion of) the Owner information and for answering subject queries. A relevant issue in this architecture is how the Owner can ensure a secure and selective publishing of its data, even if the data are managed by a third-party, which can prune some of the nodes of the original document on the basis of subject queries and access control policies. An approach can be that of requiring the Publisher to be trusted with regard to the considered security properties. However, the serious drawback of this solution is that large Web-based systems cannot be easily verified to be secure and can be easily penetrated. For these reasons, we propose an alternative approach, based on the use of digital signature techniques, which does not require the Publisher to be trusted. The security properties we consider are authenticity and completeness of a query response, where completeness is intended with regard to the access control policies stated by the information Owner. In particular, we show that, by embedding in the query response one digital signature generated by the Owner and some hash values, a subject is able to locally verify the authenticity of a query response. Moreover, we present an approach that, for a wide range of queries, allows a subject to verify the completeness of query results. Elisa Bertino, Barbara Carminati, Elena Ferrari 0001, Bhavani Thuraisingham, Amar Gupta |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2003 | A Flexible Authentication Method for UDDI Registries
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
ICWS | 2 |
| 2002 | A temporal key management scheme for secure broadcasting of XML documentsabstractSecure broadcasting of web documents is becoming a crucial need for many web-based applications. Under the broadcast document dissemination strategy a web document source periodically broad-casts (portions of) its documents to a possibly large community of subjects, without the need of explicit subject requests. By secure broadcasting we mean that the delivery of information to sub-jects must obey the access control policies of the document source. Since different subjects may have the right to access different portions of the same document, enforcing secure broadcasting requires to efficiently manage a large number of different physical views of the requested document and sending them to the proper subjects. In this paper we present an approach to secure broadcasting of web documents, based on the use of encryption techniques, and supporting the specification of fine-grained temporal access control policies. The idea is to generate a unique encrypted copy of the document to be released, where different portions of the docu-ment are encrypted with different keys, on the basis of the specified access control policies. Each subject then obtains the secret keys corresponding to document portions he/she is authorized to access. The key aspect of our approach is that the number of keys to be generated does not depend on the number of subjects nor on the document dimension, but only on the number of specified access control policies and the associated temporal constraints. Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
CCS | 2 |
| 2001 | A Secure Publishing Service for Digital Libraries of XML Documents
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
ISC | 2 |
| 2001 | XML security
Elisa Bertino, Barbara Carminati, Elena Ferrari 0001 |
Inf. Secur. Tech. Rep. | 2 |