EDBT 2026 Demo / reviewers in the wild / expert
Massimiliano Rak
dblp:90/6488
· DBLP profile ↗
78ranked-venue papers
15as first author
17since 2021 · last 2025
0000-0001-6708-4032ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 12 · 3 first-author · 1 since 2021Security and privacy · 10 · 2 first-author · 3 since 2021Systems, architecture and hardware · 9Software engineering, systems software and programming languages · 4 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Computer networks · 2Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Cyclical Penetration Testing Automation Methodology: The JetRacer Case Study
Daniele Granata, Massimiliano Rak, Felice Moretta, Fabio Fiumara |
AINA (2) | 2 |
| 2025 | NLP-Driven Analysis of Users' Reaction for Estimation of Information Disorder Propagation
Gennaro Junior Pezzullo, Alba Amato, Beniamino Di Martino, Daniele Granata, Massimiliano Rak, Salvatore Venticinque |
AINA (8) | 5 |
| 2025 | Biomechanical Data for Activity Recognition in E-Sports and the Metaverse: An Agnostic Model and Analysis Framework
Massimiliano Rak, Umberto Barbato, Francesco Grimaldi |
AINA (8) | 1 |
| 2025 | Enhancing Security in E-Sports Events: Approach to Cheating Mitigation Using Kiosk Systems
Massimiliano Rak, Umberto Barbato, Antonio Liberti |
AINA (8) | 1 |
| 2025 | Network Traffic Analysis Framework for E-Sports: The UPSIDE Dataset
Massimiliano Rak, Paolo Palmiero, Felice Moretta |
AINA (6) | 1 |
| 2025 | A Novel Semi-Automatic Approach for Security Risk Treatment for U-Space SolutionsabstractThe European U-space initiative is expected to drive the widespread adoption of drones, which in turn increases the risk of novel and evolving cyberattacks. Consequently, it is essential to prioritize the assessment and treatment of security risks within the design of U-space solutions. As part of the process, security controls must be selected and implemented to strengthen the system’s cybersecurity posture. However, such selection must take into account their costs, effectiveness, and efficiency. On the other hand, choosing the wrong security controls can leave the analyzed solution highly exposed to threat scenarios. Accordingly, manual security risk treatment could be impractical, especially for highly automated and interconnected systems like U-space. This paper introduces an innovative semi-automatic approach for the security risk treatment of U-space solutions, introducing a bridging between some established frameworks. In detail, the work proposes a systematic integration between the NIST CyberSecurity Framework (CSF) and the Security Risk Assessment Methodology (SecRAM), with the latter representing the main point of reference within the Single European Sky ATM Research (SESAR) programme. The paper demonstrates the effectiveness and cost-efficiency of the approach in developing secure U-space systems through a case study on pharmaceutical delivery in a U-space environment. Raffaele Elia, Massimiliano Rak, Domenico Pascarella |
SMC | 2 |
| 2024 | Advancing ESSecA: a step forward in Automated Penetration TestingabstractThe growing importance of Information Technology (IT) services is accompanied by a surge in security challenges. While traditional security tests focus on single applications, today’s interconnected systems require a broader evaluation. Vulnerability Assessment and Penetration Testing (VAPT) is a method to tackle this, aiming to assess whole systems thoroughly. However, performing VAPT manually is time-consuming and costly. Therefore, there’s a strong need for automating these processes. In response to these challenges, a novel methodology, named ESSecA built upon existing literature to guide the penetration testers during the assessment of a system based on threat intelligence mechanisms. This paper presents enhancements to the ESSecA methodology, including a formal Penetration Test Plan (PTP) model, a taxonomy for Penetration Test phases, and an innovative pattern match system integrated with a Tool Catalogue knowledge base used to improve the Expert System. These developments culminated in an algorithm facilitating the automatic generation of Penetration Test Plans, thus advancing the automation of security assessment processes. Massimiliano Rak, Felice Moretta, Daniele Granata |
ARES | 1 |
| 2024 | DEFEDGE: Threat-Driven Security Testing and Proactive Defense Identification for Edge-Cloud Systems
Valentina Casola, Marta Catillo, Alessandra De Benedictis, Felice Moretta, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
AINA (5) | 6 |
| 2024 | Navigating IoT Complexity: Developing Datasets for Smart-Home Device Interactions
Massimiliano Rak, Daniele Granata, Antonio Esposito 0001, Antonio Ferretti |
CISIS | 1 |
| 2024 | Systematic Threat Modelling of High-Performance Computing Systems: The V: HPCCRI Case Study
Raffaele Elia, Daniele Granata, Massimiliano Rak |
CLOSER | 3 |
| 2024 | Systematic analysis of automated threat modelling techniques: Comparison of open-source toolsabstractAbstract Companies face increasing pressure to protect themselves and their customers from security threats. Security by design is a proactive approach that builds security into all aspects of a system from the ground up, rather than adding it on as an afterthought. By taking security into account at every stage of development, organizations can create systems that are more resistant to attacks and better able to recover from them if they do occur. One of the most relevant practices is threat modelling, i.e. the process of identifying and analysing the security threat to an information system, application, or network. These processes require security experts with high skills to anticipate possible issues: therefore, it is a costly task and requires a lot of time. To face these problems, many different automated threat modelling methodologies are emerging. This paper first carries out a systematic literature review (SLR) aimed at both having an overview of the automated threat modelling techniques used in literature and enumerating all the tools that implement these techniques. Then, an analysis was carried out considering four open-source tools and a comparison with our threat modelling approach using a simple, but significant case study: an e-commerce site developed on top of WordPress. Daniele Granata, Massimiliano Rak |
Softw. Qual. J. | 2 |
| 2023 | Automated threat modelling and risk analysis in e-Government using BPMNabstractRecent progress integrates security requirements into BPMN, enhancing its framework. Extensions aim to seamlessly embed security concepts, yet the inherent ambiguity of security terms may lead to misinterpretations and vulnerabilities. Unfortunately, many business process experts lack the expertise to accurately interpret and integrate vital security concepts. In this study, we present an innovative automated methodology tailored to assist business process experts in identifying security threats and conducting risk assessments, particularly in the context of e-Government processes. Our approach streamlines the process, requiring only a business specialist to annotate BPMN entities with high-level, non-security-related information. Based on these annotations, potential threats to the system can be automatically identified. To develop our methodology, we leverage the standard BPMN annotation mechanism. From the annotated BPMN, the methodology utilises the ENISA Threat Landscape knowledge base for threat identification and employs the OWASP Risk Rating Methodology for risk assessment. To demonstrate the effectiveness of our approach, we applied it to a straightforward case study within the e-Government domain. Through this example, we illustrate how our methodology can be employed to ensure compliance with the General Data Protection Regulation and meet the mandatory Data Protection Impact Assessment requirements. Daniele Granata, Massimiliano Rak, Giovanni Salzillo, Giacomo Di Guida, Salvatore Petrillo |
Connect. Sci. | 2 |
| 2022 | MetaSEnD: A Security Enabled Development Life Cycle Meta-ModelabstractThe growing adoption of IT infrastructures determined a high heterogeneity of software systems. As matter of fact, the software is prone to vulnerabilities and cybersecurity problems, which are challenging to manage during the software lifecycle. The situation is further compounded by the growing demand for rapid application development and the widespread diffusion of Agile methodologies and the DevOps culture. This process promotes collaboration within and between the different groups involved in software development. In recent years there has been a spread of new or adapted security-oriented methodologies providing different approaches to identify security problems in the early stages of the software development life cycle (SDLC), thus reducing the costs for the security assessment. SecDevOps is just an example of the integration and promotion of security aspects in DevOps organizations. While these methodologies help to produce more reliable software, on other hand they are difficult to integrate into standard or customized SDLC, or with design evaluation and risk management methodologies. This work analyzes the state of the art and aims at identifying the main activities in a Secure Software Development Life Cycle (SSDLC), by proposing a new secure software development lifecycle meta-model (MetaSEnD). MetaSEnD has also been applied in a continuous integration pipeline of a sample microservices application. Daniele Granata, Massimiliano Rak, Giovanni Salzillo |
ARES | 2 |
| 2022 | A Semantic Methodology for Security Controls Verification in Public Administration Business Processes
Massimiliano Rak, Daniele Granata, Beniamino Di Martino, Luigi Colucci Cante |
CISIS | 1 |
| 2021 | Design and Development of a Technique for the Automation of the Risk Analysis Process in IT Security
Daniele Granata, Massimiliano Rak |
CLOSER | 2 |
| 2021 | A Conceptual Model for the General Data Protection Regulation
Pasquale Cantiello, Michele Mastroianni, Massimiliano Rak |
ICCSA (8) | 3 |
| 2021 | Demystifying the role of public intrusion datasets: A replication study of DoS network traffic data
Marta Catillo, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
Comput. Secur. | 3 |
| 2020 | A case study on the representativeness of public DoS network traffic data for cybersecurity researchabstractThe availability of ready-to-use public security datasets is fostering measurement-driven research by a wide community of academics and practitioners. Recent trends in this area put forth a substantial body of literature on anomaly and attack detection on the top of public labelled datasets. Much of this literature blindly reuses existing datasets by overlooking the cybersecurity facets of the network traffic therein, in terms of its real impact on service availability and performance of operations. Marta Catillo, Antonio Pecchia, Massimiliano Rak, Umberto Villano |
ARES | 3 |
| 2020 | Threat Modeling based Penetration Testing: The Open Energy Monitor Case studyabstractCurrently, the widespread diffusion of intelligent objects connected to the Internet and continuously interacting with people is a fact. However, such a paradigm has a side effect in terms of privacy and security: personal data and the control of critical devices (eg. boiler, air conditioning, video surveillance, controlled gates, ...) are often demanded to home automation systems, often managed by non-expert users and, consequently, likely exposed to multiple security threats. This article follows a research line that aims to offer a systematic way to identify threats in the Internet of Things systems, and consequently plan penetration testing procedures, automated as much as possible, that outline possible security holes and help to gain awareness on the issues related to this new technologies. In this paper, we addressed a typical home system, the Open Energy Monitor, to demonstrate our methodology. In this analysis we focus on the MQTT protocol, commonly used for communication between IoT devices, proposing a complete Threat Model for this protocol. The main innovative contribution of this paper relates to the catalog of threats made available for MQTT-based devices (highly reusable in different environments) and on the planning of penetration tests, that relies on the adoption of a cyber threat intelligence database that collects common attack patterns, offered by MITRE. Giovanni Salzillo, Massimiliano Rak, Felice Moretta |
SIN | 2 |
| 2020 | Auto-scaling Applications in the Cloud by Simple Indexes with Complex LoadsabstractApplications executed in the cloud can exploit its elasticity features, varying dynamically the amount of leased resources so as to adapt to load variations and to guarantee quality of service. As auto-scaling has implications on execution costs, making optimal scaling choices is of paramount importance. This paper presents an analysis method based on offline benchmarking and simple models that allows to evaluate performance indexes useful to define scaling policies to be used by auto-scalers. The proposed approach relies on a fixed set of benchmarks, to be executed off-line and a set of models that enable prediction of the same performance indexes under different workload conditions, enabling the analyst to perform parameter analysis when defining an auto-scaling policy. Marta Catillo, Luciano Ocone, Massimiliano Rak, Umberto Villano |
WETICE | 3 |
| 2020 | A novel Security-by-Design methodology: Modeling and assessing security by SLAs with a quantitative approach
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
J. Syst. Softw. | 3 |
| 2019 | Optimization and Validation of eGovernment Business Processes with Support of Semantic Techniques
Beniamino Di Martino, Alfonso Marino, Massimiliano Rak, Paolo Pariso |
CISIS | 3 |
| 2019 | Benchmark-Based Cost Analysis of Auto Scaling Web Applications in the CloudabstractApplications executed in the cloud can exploit its elasticity features, varying dynamically the amount of leased resources so as to adapt to load variations and to guarantee good quality of service. As auto scaling has severe implications on execution costs, making optimal scaling choices is of paramount importance. This paper presents an analysis method based on off-line benchmarking that allows to define scaling policies to be used by auto-scalers. The indexes obtained by benchmarking multiple deployment configurations can be used on-line, to scale the application making a trade-off between cost and user-perceived performance. Luciano Ocone, Massimiliano Rak, Umberto Villano |
WETICE | 2 |
| 2019 | WETICE 2019 - General TrackabstractThe International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises WETICE is an international forum for state-of the-art research in enabling technologies for collaboration. The 28th WETICE edition takes place on June 12-14, 2019 in Capri (Napoli), Italy and it is made of eleven scientific tracks. Massimiliano Rak |
WETICE | 1 |
| 2019 | Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systemsabstractCompliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud‐based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end‐users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk‐driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime. Erkuden Rios, Eider Iturbe, Xabier Larrucea, Massimiliano Rak, Wissam Mallouli, Jacek Dominiak, Victor Muntés-Mulero, Peter Matthews, Luis Gonzalez |
IET Softw. | 4 |
| 2018 | A Proposal of a Cloud-Oriented Security and Performance Simulator Provided as-a-Service
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CISIS | 3 |
| 2018 | Towards Automated Penetration Testing for Cloud ApplicationsabstractThe development of cloud applications raises several security concerns due to the lack of control over involved resources. Security testing is fundamental to identify the existing security issues and is particularly powerful when carried out by means of penetration testing techniques. Unfortunately, penetration testing requires a deep knowledge of the possible attacks and of the available hacking tools and is very energy demanding. In this paper, we present a methodology that allows to easily carry out a coarse-grained security evaluation of a cloud application by automating the set-up and execution of penetration tests. The methodology relies on the knowledge of the application architecture and on the availability of a catalogue including security-related data collected from multiple sources and properly correlated. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
WETICE | 3 |
| 2018 | Security-by-design in multi-cloud applications: An optimization approach
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
Inf. Sci. | 3 |
| 2017 | A Security Metric Catalogue for Cloud Applications
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CISIS | 3 |
| 2017 | An Automatic Tool for Benchmark Testing of Cloud Applications
Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CLOSER | 3 |
| 2017 | Security Assurance of (Multi-)Cloud Application with Security SLA Composition
Massimiliano Rak |
GPC | 1 |
| 2017 | Secure microGRID in Cloud: The CoSSMic Case Study
Massimiliano Rak, Salvatore Venticinque |
GPC | 1 |
| 2017 | MUSA Deployer: Deployment of Multi-cloud ApplicationsabstractThe development of applications based on services offered by different, not conscious, providers, is expected to be growing in the next years. In order to offer effectively multicloud applications, many challenges still need to be faced. At this aim, the MUSA framework provides a DevOps approach to develop multi-cloud applications with desired Security Service Level Agreements (SLAs). This paper describes the MUSA Deployer models, which help developers to express their security requirements, and a Deployer tool that automatically provides cloud security services to offer Security SLAs. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano, Erkuden Rios, Angel Rego, Giancarlo Capone |
WETICE | 3 |
| 2017 | Automatically Enforcing Security SLAs in the CloudabstractDealing with the provisioning of cloud services granted by Security SLAs is a very challenging research topic. At the state of the art, the main related issues involve: (i) representing security features so that they are understandable by both customers and providers and measurable (by means of verifiable security-related Service Level Objectives (SLOs)), (ii) automating the provisioning of security mechanisms able to grant desired security features (by means of a security-driven resource allocation process), and (iii) continuously monitoring the services in order to verify the fulfillment of specified Security SLOs (by means of cloud security monitoring solutions). We propose to face the Security SLA life cycle management with a framework able to enrich cloud applications with security features. In this paper we (i) present a novel Security SLA model and (ii) illustrate a security-driven planning process that can be adopted to determine the (optimum) deployment of security-related software components. Such process takes into account both specific implementation constraints of the security components to be deployed and customers security requirements, and enables the automatic provisioning and configuration of all needed resources. In order to demonstrate the applicability of the approach, we present and discuss a practical application of the model on a real case study. Valentina Casola, Alessandra De Benedictis, Madalina Erascu, Jolanda Modic, Massimiliano Rak |
IEEE Trans. Serv. Comput. | 5 |
| 2016 | A Security SLA-driven Methodology to Set-Up Security Capabilities on Top of Cloud ServicesabstractThe extensive use of cloud services by both individual users and organizations induces several security risks. The risk perception is higher when Cloud Service Providers (CSPs) do not clearly state their security policies and/or when such policies do not directly match user-defined requirements. Security-oriented Service Level Agreements (Security SLAs) represent a fundamental means to encourage the adoption of cloud services in contexts where security is mandatory. Nevertheless, despite the number of existing initiatives aimed at formalizing Security SLAs and at representing security guarantees by taking into account both customers' and providers' perspectives, they are far from being commonly adopted in practice by CSPs, due to the difficulty in automatically enforcing and monitoring the security capabilities agreed with customers. In this paper we illustrate, through a case study, a methodology to set-up a catalogue of security capabilities that can be offered as-a-service, on top of which specific guarantees can be specified through a Security SLA. Such a methodology, which explicitly takes into account the constraints behind the definition of formal guarantees related to security, is meant to serve as a guideline for providers willing to offer for their services specific security features that can be monitored and assessed by customers during operation. Valentina Casola, Alessandra De Benedictis, Madalina Erascu, Massimiliano Rak, Umberto Villano |
CISIS | 4 |
| 2016 | Methodology to Obtain the Security Controls in Multi-cloud ApplicationsabstractPublisher Copyright: Copyright © 2016 by SCITEPRESS-Science and Technology Publications, Lda. All rights reserved. Samuel Olaiya Afolaranmi, Luis E. Gonzalez Moctezuma, Massimiliano Rak, Valentina Casola, Erkuden Rios, José L. Martínez Lastra |
CLOSER (1) | 3 |
| 2016 | Providing Security SLA in Next Generation Data Centers with SPECS: The EMC Case StudyabstractNext generation Data Centers (ngDC) are the cloud-based architectures devoted to offering infrastructure services in flexible ways: managing in an integrated way compute, network and storage services. This solution is very attractive from an organisation’s perspective but one of the main challenges to adoption is the perception of loss of security and control over resources that are dynamically acquired in the cloud and that reside on remote providers. For a full adoption, datacenter customers need more guarantees about the security levels provided, creating the need for tools to dynamically negotiate and monitor the security requirements. The SPECS project proposes a platform that offers security features with an as-a-service approach, furthermore it uses Security Service Level Agreements (Security SLA) as a means for establishing a clear statement between customers and providers to define a mutual agreement. This paper presents an industrial experience from EMC that integrates the SPECS Platform and their innovative solutions for ngDC. In particular, the paper will illustrate how it is possible to negotiate, enforce and monitor a Security SLA in a cloud infrastructure offering. Valentina Casola, Massimiliano Rak, Isidoro S. La Porta, Andrew Byrne |
CLOSER (2) | 2 |
| 2016 | On the Next Generations of Infrastructure-as-a-ServicesabstractFollowing the wide adoption by industry of the cloud computing technologies, we can talk about a second generation of cloud services and products that are currently under design phase. However, it is not yet clear how the third generation of cloud products and services of the next decade will look like, especially at the delivery level of Infrastructure-as-a-Service. In order to answer at least partially to such a challenging question, we initiated a literature overview and two surveys involving the members of a cluster of European research and innovation actions. The results are interpreted in this paper and a set of topics of interest for the third generation are identified. Dana Petcu, Maria Fazio, Radu Prodan, Zhiming Zhao, Massimiliano Rak |
CLOSER (1) | 5 |
| 2016 | Towards a Proof-based SLA Management Framework - The SPECS ApproachabstractWe present a framework that allows monitoring of the cloud-based applications and environments to verify fulfilment of Service Level Agreements (SLAs), to analyse and remediate detectable security breaches that compromise the validity of SLAs related to storage services. In particular, we describe a system to facilitate identification of the root cause of each violation of integrity, write-serializability and read-freshness properties. Such a system enables executing remediation actions specifically planned for detectable security incidents. The system is activated in an automated way on top of storage services, according to an SLA, which can be negotiated with customers. Miha Stopar, Jolanda Modic, Dana Petcu, Massimiliano Rak |
CLOSER (2) | 4 |
| 2016 | Per-Service Security SLa: A New Model for Security Management in CloudsabstractIn the cloud computing context, Service Level Agreements (SLAs) are contracts between Cloud Service Providers (CSPs) and Cloud Service Customers (CSCs), stating the guaranteed quality level of the services offered by CSPs. Existing cloud SLAs focus only on few service terms, completely ignoring all security related aspects. They are often reported in a way that is hardly understandable for customers. Moreover, they offer guarantees uniform for all offered services and all customers, regardless of particular service characteristics or customers specific needs. This paper presents a framework that enables the adoption of a per-service SLA model, by supporting the automatic implementation of cloud Security SLAs tailored to the needs of each customer for specific service instances. In particular, the process and the software architecture for per-service SLA implementation are shown. A case study application demonstrates the feasibility and effectiveness of the proposed solution. Valentina Casola, Alessandra De Benedictis, Jolanda Modic, Massimiliano Rak, Umberto Villano |
WETICE | 4 |
| 2015 | Security Monitoring in the Cloud: An SLA-Based ApproachabstractIn this paper we present a monitoring architecture that is automatically configured and activated based on a signed Security SLA. Such monitoring architecture integrates different security-related monitoring tools (either developed ad-hoc or already available as open-source or commercial products) to collect measurements related to specific metrics associated with the set of security Service Level Objectives (SLOs) that have been specified in the Security SLA. To demonstrate our approach, we discuss a case study related to detection and management of vulnerabilities and illustrate the integration of the popular open source monitoring system Open VAS into our monitoring architecture. We show how the system is configured and activated by means of available Cloud automation technologies and provide a concrete example of related SLOs and metrics. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak |
ARES | 3 |
| 2015 | Towards Self-Protective Multi-Cloud Applications - MUSA - a Holistic Framework to Support the Security-Intelligent Lifecycle Management of Multi-Cloud ApplicationsabstractThe most challenging applications in heterogeneous cloud ecosystems are those that are able to maximise the benefits of the combination of the cloud resources in use: multi-cloud applications. They have to deal with the security of the individual components as well as with the overall application security including the communications and the data flow between the components. In this paper we present a novel approach currently in progress, the MUSA framework. The MUSA framework aims to support the security-intelligent lifecycle management of distributed applications over heterogeneous cloud resources. The framework includes security-by-design mechanisms to allow application self-protection at runtime, as well as methods and tools for the integrated security assurance in both the engineering and operation of multi-cloud applications. The MUSA framework leverages security-by-design, agile and DevOps approaches to enable the security-aware development and operation of multi-cloud applications. Erkuden Rios, Eider Iturbe, Leire Orue-Echevarria Arrieta, Massimiliano Rak, Valentina Casola |
CLOSER | 4 |
| 2015 | REST-Based SLA Management for Cloud ApplicationsabstractIn cloud computing, possible risks linked to availability, performance and security can be mitigated by the adoption of Service Level Agreements (SLAs) formally agreed upon by cloud service providers and their users. This paper presents the design of services for the management of cloud-oriented SLAs that hinge on the use of a REST-based API. Such services can be easily integrated into existing cloud applications, platforms and infrastructures, in order to support SLA-based cloud services delivery. After a discussion on the SLA life-cycle, an agreement protocol state diagram is introduced. It takes explicitly into account negotiation, remediation and renegotiation issues, is compliant with all the active standards, and is compatible with the WS-Agreement standard. The requirement analysis and the design of a solution able to support the proposed SLA protocol is presented, introducing the REST API used. This API aims at being the basis for a framework to build SLA-based applications. Alessandra De Benedictis, Massimiliano Rak, Mauro Turtur, Umberto Villano |
WETICE | 2 |
| 2015 | Planting parallel program simulation on the cloudabstractSummary The writing of efficient parallel code has always been a tedious and time‐consuming process. However, the performance prediction prototype tools devised in the last decade come of age now, thanks to the availability of the almost unlimited computing power of clouds. This paper presents the practical use of mJADES, a novel environment for running multiple concurrent simulations in the cloud, to predict the performance of parallel code in multiple working conditions at once. After an introduction on mJADES and its operational aspects, the construction of parallel code performance prediction models will be dealt with. The models and the results obtained for a simple but complete and meaningful case study will be presented, discussing the accuracy obtained by simulation and the time required for performing the whole set of simulations necessary to characterize the program behavior. Copyright © 2013 John Wiley & Sons, Ltd. Antonio Cuomo, Massimiliano Rak, Umberto Villano |
Concurr. Comput. Pract. Exp. | 2 |
| 2015 | Stealthy Denial of Service Strategy in Cloud ComputingabstractThe success of the cloud computing paradigm is due to its on-demand, self-service, and pay-by-use nature. According to this paradigm, the effects of Denial of Service (DoS) attacks involve not only the quality of the delivered service, but also the service maintenance costs in terms of resource consumption. Specifically, the longer the detection delay is, the higher the costs to be incurred. Therefore, a particular attention has to be paid for stealthy DoS attacks. They aim at minimizing their visibility, and at the same time, they can be as harmful as the brute-force attacks. They are sophisticated attacks tailored to leverage the worst-case performance of the target system through specific periodic, pulsing, and low-rate traffic patterns. In this paper, we propose a strategy to orchestrate stealthy attack patterns, which exhibit a slowly-increasing-intensity trend designed to inflict the maximum financial cost to the cloud customer, while respecting the job size and the service arrival rate imposed by the detection mechanisms. We describe both how to apply the proposed strategy, and its effects on the target system deployed in the cloud. Massimo Ficco, Massimiliano Rak |
IEEE Trans. Cloud Comput. | 2 |
| 2014 | Preliminary Design of a Platform-as-a-Service to Provide Security in CloudabstractCloud computing is an emerging paradigm, recently widely adopted in distributed and business computing.
Even if it is very attractive, due to its business model (pay-per-use) and its flexibility (self-service on demand approach), one of the main limits for its adoption is the perception of loss of security and control over resources that are dynamically acquired in the cloud and that reside on remote providers.
Moreover, security mechanisms are usually integrated into system architectures, and are not offered to users in a way that enables customization and is easy to use. As a consequence, as far as security is concerned, cloud customers are usually tied to a limited set of offerings made available by providers, often without real grants about the way in which such mechanisms are actually implemented and enforced.
This paper deals with the architecture underlying the SPECS platform, which aims at offering security features by an as-a-service approach, using Service Level Agreements as a mean for clear statement between customers and providers to define mutual rights and constraints.
The goal is to show the main requirements of such platform and to present the global architecture, in terms of components and their interactions, dedicated to negotiate, to monitor and to enforce the security mechanisms to be applied over existing cloud providers. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Umberto Villano |
CLOSER | 3 |
| 2014 | A Cloud Application for Security Service Level Agreement EvaluationabstractCloud security is today considered the main limit to a widespread adoption of Cloud Computing. In this paradigm, due to the serlf-service on-demand characteristic, all data, servers infrastructures resides on the cloud and charged on a pay-per-use basis.
If this implies great advantages from business point of view, because there are no maintenance and start-up costs for infrastructures, there is the perception of a loss of control over the resources, that impacts the security requirements.
Academic works and the Cloud community (e.g., work-groups at the European Network and Information Security Agency, ENISA) have identified that specifying security parameters in Service Level Agreements actually enables the establishment of a common semantic in order to model security among users and Cloud Service providers (CSPs).
However, despite the state of the art efforts aiming at building and representing Cloud SecLAs there is still a gap on the techniques to reason about them. Moreover a lot of activities are being carrying out to clearly state which are the parameters to be shared, their meanings and how they affect service provisioning.
In this paper we propose to build up cloud applications that are able to offer Security level Evaluation over SLA expressed in many different ways. Such applications can be offered as a service by Third Parties in order to help customers to evaluate the offerings from providers.
Such application can be used in order to help customers to negotiate security parameters in a Multi-Cloud system and perform Cloud brokering on the basis of a quantitative evaluation of security parameters. Valentina Casola, Massimiliano Rak, Giuseppe Alfieri |
CLOSER | 2 |
| 2014 | Cloud-Aware Development of Scientific ApplicationsabstractThe potential of cloud computing is still underutilized in the scientific computing field. Even if clouds probably are not fit for high-end HPC applications, they could be profitably used to bring the power of economic and scalable parallel computing to the masses. But this requires simple and friendly development environments, able to exploit cloud scalability and to provide fault tolerance. This paper presents a framework built on the top of a cloud-aware platform (mOSAIC) for the development of bag-of-tasks scientific applications. Alessandra De Benedictis, Massimiliano Rak, Mauro Turtur, Umberto Villano |
WETICE | 2 |
| 2013 | Negotiating and Brokering Cloud Resources based on Security Level Agreements
Jesus Luna, Tsvetoslava Vateva-Gurova, Neeraj Suri, Massimiliano Rak, Loredana Liccardo |
CLOSER | 4 |
| 2013 | An SLA-Based Approach to Manage Sensor Networks as-a-ServiceabstractThe integration of sensing infrastructures into the Cloud gives a number of advantages in providing sensor data as a service over the Internet. Many solutions are now available in the literature, and most of them focus on modeling sensor networks as part of the infrastructure to be offered as a service (IaaS), directly managed by means of the Cloud tools that provide resource virtualization. We propose a different approach: sensor networks are modeled as providers that offer their resources to a Cloud application that runs independently from Cloud providers. Being offered as a Service, any user can negotiate with the provider his desired requirements in terms of operational parameters and non-functional features (i.e. security, dependability, etc). In particular, we propose a SLA-based approach for the specification and management of usage term guarantees related to the access and configuration of private sensor networks. To this end, a Cloud Sensing Brokering Platform is designed to illustrate the innovative way to integrate Cloud and Sensor Networks. Valentina Casola, Alessandra De Benedictis, Massimiliano Rak, Giuseppe Aversano, Umberto Villano |
CloudCom (1) | 3 |
| 2013 | Security as a Service Using an SLA-Based Approach via SPECSabstractThe cloud offers attractive options to migrate corporate applications, without any implication for the corporate security manager to manage or to secure physical resources. While this ease of migration is appealing, several security issues arise: can the validity of corporate legal compliance regulations still be ensured for remote data storage? How is it possible to assess the Cloud Service Provider (CSP) ability to meet corporate security requirements? Can one monitor and enforce the agreed cloud security levels? Unfortunately, no comprehensive solutions exist for these issues. In this context, we introduce a new approach, named SPECS. It aims to offer mechanisms to specify cloud security requirements and to assess the security features offered by CSPs, and to integrate the desired security services (e.g., credential and access management) into cloud services with a Security-as-a-Service approach. Furthermore, SPECS intends to provide systematic approaches to negotiate, to monitor and to enforce the security parameters specified in Service Level Agreements (SLA), to develop and to deploy security services that are cloud SLA-aware and are implemented as an open-source Platform-as-a-Service (PaaS). This paper introduces the main concepts of SPECS. Massimiliano Rak, Neeraj Suri, Jesus Luna, Dana Petcu, Valentina Casola, Umberto Villano |
CloudCom (2) | 1 |
| 2013 | The CloudGrid approach: Security analysis and performance evaluation
Valentina Casola, Antonio Cuomo, Massimiliano Rak, Umberto Villano |
Future Gener. Comput. Syst. | 3 |
| 2013 | An SLA-based Broker for Cloud Infrastructures
Antonio Cuomo, Giuseppe Di Modica, Salvatore Distefano, Antonio Puliafito, Massimiliano Rak, Orazio Tomarchio, Salvatore Venticinque, Umberto Villano |
J. Grid Comput. | 5 |
| 2012 | Intrusion Tolerance in Cloud Applications: The mOSAIC ApproachabstractCloud Computing is a recognized emerging solution for building Internet applications, which founds on delegation of every kind of resources to the network and on a pay-per-use business model. Cloud application, which runs consuming Cloud resources offered by Cloud Providers, offers open interfaces to their users, which access them from Internet and are often prone to Denial of Services attacks. This work focuses on the mosaic approach for development of Cloud applications, which offers a solution for gathering resources from many different providers. It shows how it is possible to enrich the mosaic platform with tools that, in a simple and transparent way, protect mosaic Cloud application from some well known Denial of Services attacks. The paper focuses on a single kind of attacks, called Deeply-Nested XML, in order to show the proposed approach and offer some preliminary results, which demonstrate the validity of the solution proposed. Massimo Ficco, Massimiliano Rak |
CISIS | 2 |
| 2012 | mJADES: Concurrent Simulation in the CloudabstractThe simulation of complex systems is a time expensive and resource consuming task. Furthermore, the statistical validation of simulation models or the need to compare the system behavior in several different conditions require many simulation runs. A viable solution to speed up the process is to run multiple simulations in parallel on a distributed system, for example by means of a web interface. In this context, the cloud computing paradigm can be of help, offering almost unlimited computing resources that can be leased as a service. In this paper we will present the structure of a new simulation engine " in thecloud" (mJADES), which runs on the top of an ad-hoc federation of cloud providers and is designed to perform multiple concurrent simulations. Given a set of simulation tasks, mJADES is able automatically to acquire the computing resources needed from the cloud and to distribute the simulation runs to be executed. Massimiliano Rak, Antonio Cuomo, Umberto Villano |
CISIS | 1 |
| 2012 | SLA Negotiation and Brokering for Sky Computing
Alba Amato, Loredana Liccardo, Massimiliano Rak, Salvatore Venticinque |
CLOSER | 3 |
| 2012 | Intrusion Tolerance as a Service - A SLA-based Solution
Massimiliano Rak, Massimo Ficco |
CLOSER | 1 |
| 2012 | Negotiation Policies for Provisioning of Cloud Resources
Salvatore Venticinque, Viorel Negru, Victor Ion Munteanu, Calin Sandru, Rocco Aversa, Massimiliano Rak |
ICAART (2) | 6 |
| 2012 | Intrusion Tolerance of Stealth DoS Attacks to Web Services
Massimo Ficco, Massimiliano Rak |
SEC | 2 |
| 2012 | Process-oriented Discrete-event Simulation in Java with Continuations - Quantitative Performance Evaluation
Antonio Cuomo, Massimiliano Rak, Umberto Villano |
SIMULTECH | 2 |
| 2011 | A SLA-based interface for security management in cloud and GRID integrationsabstractCloud Computing is a new computing paradigm. Among the incredible number of challenges in this field two of them are considered of great relevance: SLA management and Security management. The level of trust in such context is very hard to define and is strictly related to the problem of management of SLA in cloud applications and providers. In this paper we will try to show how it is possible, using a cloud-oriented API derived from the mOSAIC project, to build up an SLA-oriented cloud application which enables the management of security features related to user authentication and authorization to an Infrastructure as a Service (IaaS) Cloud Provider. As Cloud Provider we will adopt the perf-Cloud solution, which uses GRID-based solutions for security management and service delivery. So the proposed solution can be used in order to build up easily a SLA-based interface for any GRID system. Massimiliano Rak, Loredana Liccardo, Rocco Aversa |
IAS | 1 |
| 2011 | The Cloud@Home Architecture - Building a Cloud Infrastructure from Volunteered Resources
Antonio Cuomo, Giuseppe Di Modica, Salvatore Distefano, Massimiliano Rak, Alessio Vecchio |
CLOSER | 4 |
| 2011 | Towards a Cross Platform Cloud API - Components for Cloud Federation
Dana Petcu, Ciprian Craciun, Massimiliano Rak |
CLOSER | 3 |
| 2011 | Cloud Application Monitoring: The mOSAIC ApproachabstractCloud computing delegates the management of any kind of resources, such as the computing environment or storage systems for example, to the network. The wide-spread permeation of the cloud paradigm implies the need of new programming models that are able to utilize such new features. Once the problem of enabling developers to manage cloud resources in a clear and flexible way is solved, a new problem emerges: the monitoring of the quality of the acquired resources and of the services offered to final users. As the first step, the mOSAIC API and framework aim at offering a solution for the development of interoperable, portable and cloud-provider independent cloud applications. As the second step, this paper introduces the mOSAIC monitoring components that facilitate the building of custom monitoring systems for cloud applications using the mOSAIC API. Massimiliano Rak, Salvatore Venticinque, Tamás Máhr, Gorka Mikel Echevarria Velez, Gorka Esnal |
CloudCom | 1 |
| 2010 | Identity federation in cloud computingabstractBoth cloud and GRID are computing paradigms for the large-scale management of distributed resources. Even if the first is usually oriented to transaction-based applications, and the latter to High Performance Computation, there is a lot of interest in their integration. This is typically obtained through the Infrastructure-as-a-Service cloud model, which is exploited in the GRID context to offer machine with full administration rights to users. In this paper the focus is on the security problems linked to the integration of cloud and GRID computing. It is proposed the adoption of identify federation between different security domains to manage the relationship between the user machines and the standard GRID infrastructure. This solution is experimented within PerfCloud, a cloud implementation that exploits an underlying GRID platform. Valentina Casola, Massimiliano Rak, Umberto Villano |
IAS | 2 |
| 2010 | Cloud Agency: A Mobile Agent Based Cloud SystemabstractThe cloud paradigm appeared on the computing scene in 2005 with the Amazon Elastic Compute Cloud (EC2). After this date, a large set of related technologies has been developed. In the academic world, and especially in the HPC area, cloud computing is in some way in competition with the GRID model, which offers a middleware based approach. One of the solutions proposed is the integration of the two paradigms, in order to use the enormous potential of the existent computational GRIDs in new ways. One of the most diffused problems on this systems is the choice of the correct programming paradigm: many different approaches exist and it is difficult to define which is the approach that best fit with the cloud paradigm. In this paper we propose the integration of a Cloud on GRID architecture with a mobile agent platform. The architecture we propose offer Virtual clusters with full administrative control to final users, adopting an existent GRID architecture and especially its security infrastructure. The mobile agent platform is able to dynamically add and configure services on the virtual clusters. The experience here presented shows that the mobile agent paradigm well fulfills the dynamic properties of the Cloud paradigm and could be a good choice to simply develop application and services able to dynamically adapt themselves to the virtualized environment. Rocco Aversa, Beniamino Di Martino, Massimiliano Rak, Salvatore Venticinque |
CISIS | 3 |
| 2010 | Autonomic Composite-service Architecture with MAWeSabstractThe highly distributed nature and the load sensitivity of Service Oriented Architectures (SOA) make it very difficult to guarantee performance requirements under rapidly-changing load conditions. This paper deals with the development of service oriented autonomic systems that are capable to optimize themselves using a feed forward approach, by exploiting automatically generated performance predictions. The MAWeS (MetaPL/HeSSE Autonomic Web Services) framework allows the development of self-tuning applications that proactively optimize themselves by simulating the execution environment. After a discussion on the possible design choices for the development of autonomic web services applications, a soft real-time test application is presented and the performance results obtained in a composite-service execution scenario are commented. Emilio Pasquale Mancini, Massimiliano Rak, Umberto Villano |
CISIS | 2 |
| 2010 | Instantaneous Load Dependent Servers (iLDS) Model for Web ServicesabstractIn the last few years, the paradigms used to create new business applications is deeply changed. As matter of fact, the service providers turned their old approach create from scratch whatever we need into a new one: look for and integrate. In this brand new scenario, the key role is played by the interoperability: indeed it is required that each time a new service is deployed and once the interfaces are defined, the client does not need any further information to make use of the service. The service oriented architecture (SOA) aims at providing a structure that guarantees the transparency and the interoperability between service providers and service requestors. Even if the SOA is widely diffused, its performances evaluation is still an open problem: due to transparency of the architecture, it is very hard for application/service developers to have quantitative performance evaluation at any development stages. In this context, we will give an answer to the following question: given a newly developed service, built in a closed development environment, how to predict its performance on a hosted service platform (for example in order to choice between two available platforms or to fine tune it in the contest of a large SOA application)? In this paper we propose a technique for semiautomatic building of performance models of Web service platforms, which we model as instantaneous load dependent servers (iLDS): servers whose service time depends on the workload at a given time. The approach we propose, adopts a black box measurement technique, this means that we can just deploy a service, but we have no access to the underlying server platform configuration both for software and hardware layers. The resulting model can be used by final user or service developers to predict the service behaviour respect to a known workload or to compare different web service platforms. The proposed approach was validated on a simple case study and the measurements put in evidence an interesting result about the common behavior of instantaneous load dependent servers, which can be of general use for modeling this class of systems. Massimiliano Rak, Antonio Sgueglia |
CISIS | 1 |
| 2008 | Self-optimization of secure web services
Valentina Casola, Emilio Pasquale Mancini, Nicola Mazzocca, Massimiliano Rak, Umberto Villano |
Comput. Commun. | 4 |
| 2008 | Simulation-based optimization of multiple-task GRID applications
Emilio Pasquale Mancini, Umberto Villano, Massimiliano Rak, Francesco Moscato 0001 |
Future Gener. Comput. Syst. | 3 |
| 2007 | Building Autonomic and Secure Service Oriented Architectures with MAWeS
Valentina Casola, Emilio Pasquale Mancini, Nicola Mazzocca, Massimiliano Rak, Umberto Villano |
ATC | 4 |
| 2007 | Interoperable Grid PKIs Among Untrusted Domains: An Architectural Proposal
Valentina Casola, Jesus Luna, Oscar Manso, Nicola Mazzocca, Manuel Medina, Massimiliano Rak |
GPC | 6 |
| 2007 | A Framework for Mobile Agent Platform performance EvaluationabstractMobile agents programming paradigm is an emerging approach for distributed computing, extremely suitable for mobile systems because of its adaptability to exploit the available resources. Optimization of mobile agents applications and system configuration are relevant above all when we deal handheld devices with limited capabilities. Classical approaches are hard to apply because new kinds of interaction facilities provided by agent platforms, such as cloning and migration, represent an additional software layer that affects the system performances. In this context identification and estimation of performance indexes are necessary to evaluate and foresee system dependability. In fact performance evaluation is exploited to address different issues according to which, different measurements are required. In practice, there is a need for tools and techniques for evaluation of the performances of the adopted mobile agent platforms. Related work proposes a set of performance indexes, slightly different one from the other; and measured using different approaches. We present here a framework that aims at supporting the development of ad-hoc solutions based on measurement agents. Framework architecture, prototype implementation and case studies and preliminary performance figures are presented in the following. Rocco Aversa, Beniamino Di Martino, Massimiliano Rak, Salvatore Venticinque |
WOWMOM | 3 |
| 2007 | Cluster systems and simulation: from benchmarking to off-line performance predictionabstractAbstract This paper describes a simulation‐based technique for the performance prediction of message‐passing applications on cluster systems by means of benchmark data. Given data measuring the performance of a target cluster in the form of standard benchmark results, along with the details of the chosen computing configuration, it is possible to build and to validate automatically a detailed simulation model. This makes it possible to predict off‐line, i.e. without resorting to the real hardware, the performance of fully developed or even of skeletal code. An XML‐based language (MetaPL) is adopted to describe the application behavior in the development stage. After a description of the approach and the illustration of the construction and validation of the simulation model, the paper presents a case study. Copyright © 2006 John Wiley & Sons, Ltd. Beniamino Di Martino, Emilio Pasquale Mancini, Massimiliano Rak, Roberto Torella, Umberto Villano |
Concurr. Comput. Pract. Exp. | 3 |
| 2006 | Autonomic Web Service Development with MAWeSabstractService oriented architectures (SOA) are based on applications consisting of an aggregation of services with standard interface, offered on distributed hosts. The highly distributed nature and the load sensitivity of these architectures make it very difficult to guarantee performance requirements under rapidly-changing load conditions. This paper deals with the development of service oriented predictive autonomic systems that are capable to optimize themselves using a feedforward approach, by exploiting automatically generated performance predictions. The MAWeS (MetaPL/HeSSE autonomic Web services) framework allows the development of self-tuning applications that proactively optimize themselves by simulating the execution environment. An example of application development in MAWeS is thoroughly dealt with, showing the implementation of a system that exploits MAWeS services to choose dynamically among several different algorithms to meet response time constraints. Emilio Pasquale Mancini, Umberto Villano, Massimiliano Rak |
AINA (2) | 3 |
| 2006 | Self-optimization of MPI Applications Within an Autonomic Framework
Massimiliano Iannotta, Emilio Pasquale Mancini, Massimiliano Rak, Umberto Villano |
HPCC | 3 |
| 2005 | Self-optimizing MPI Applications: A Simulation-Based Approach
Emilio Pasquale Mancini, Massimiliano Rak, Roberto Torella, Umberto Villano |
HPCC | 2 |
| 2005 | Performance prediction through simulation of a hybrid MPI/OpenMP application
Rocco Aversa, Beniamino Di Martino, Massimiliano Rak, Salvatore Venticinque, Umberto Villano |
Parallel Comput. | 3 |