Nicola Zannone

dblp:93/4627 · DBLP profile ↗
← Back
95ranked-venue papers
3as first author
31since 2021 · last 2026
0000-0002-9081-5996ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 57 · 2 first-author · 22 since 2021Software engineering, systems software and programming languages · 18 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 8 · 3 since 2021Artificial intelligence and machine learning · 6 · 2 since 2021Computer networks · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021
YearPublicationVenuePosition
2026 From DePIN Hype to Operational Reality: Assessing Centralization and Usage of Commercial dVPNs
abstract
Decentralized VPNs (dVPNs) are marketed as a flagship use case of Decentralized Physical Infrastructure Networks (DePIN): a fully decentralized, censorship-resistant alternative to traditional VPNs, where users route traffic through a global pool of independently operated exit nodes. However, despite claims of decentralization and “military-grade privacy”, little is known in both the white and the gray literature about the actual commercial dVPNs architecture, their true level of decentralization, and what they are used for. To fill these gaps, in this work, we present the first data-driven, operator-centric study of commercial dVPNs. We deploy several fully functional exit nodes worldwide on two prominent dVPN platforms, Mysterium and Sentinel. Via such nodes, we collect control-plane traffic, user traffic, and publicly available metadata to assess what an honest-but-curious operator can infer about systems' architecture, effective decentralization, and real-world usage. Our findings challenge the dominant narrative. Architecturally, both investigated dVPNs rely heavily on centralized orchestrators, often hosted on a handful of Cloud providers. These components constitute clear chokepoints, making the networks more fragile, censorable, and way less decentralized than their branding suggests. From a usage perspective, traffic relayed by our nodes is dominated by mainstream, commercially oriented activities rather than by censorship evasion or privacy-motivated uses. Overall, we show that current commercial dVPNs inherit many centralized features of traditional VPNs while shifting trust and liability onto a heterogeneous, legally shaky, and largely untrusted operator base.
Bartan Oren, Maurantonio Caprolu, Savio Sciancalepore, Nicola Zannone, Roberto Di Pietro
AsiaCCS4
2026 SCoPE: Cross-Platform Discovery and RAG-Driven Profiling of Public Personal Data
Stefano Cirillo, Giuseppe Polese, Giandomenico Solimando, Nicola Zannone
DBSec4
2026 A Causal Framework for Explainable Access Control: [Work in Progress Paper]
Gelareh Hasel Mehri, Clemens Dubslaff, Tim A. C. Willemse, Nicola Zannone
SACMAT4
2025 Cross-Jurisdictional Compliance with Privacy Laws: How Websites Adapt Consent Notices to Regional Regulations
Xander Smeets, Michele Campobasso, Nicola Zannone
ARES (1)3
2025 The Impact of Emerging Phishing Threats: Assessing Quishing and LLM-generated Phishing Emails against Organizations
abstract
Modern organizations are persistently targeted by phishing emails. Despite advances in detection systems and widespread employee training, attackers continue to innovate, posing ongoing threats. Two emerging vectors stand out in the current landscape: QR-code baits and LLM-enabled pretexting. Yet, little is known about the effectiveness of current defenses against these attacks, particularly when it comes to real-world impact on employees. This gap leaves uncertainty around to what extent related countermeasures are justified or needed. Our work addresses this issue. We conduct three phishing simulations across organizations of varying sizes - from small-medium businesses to a multinational enterprise. In total, we send over 71k emails targeting employees, including: a "traditional"phishing email with a click-through button; a nearly-identical "quishing"email with a QR code instead; and a phishing email written with the assistance of an LLM and open-source intelligence. Our results show that quishing emails have the same effectiveness as traditional phishing emails at luring users to the landing webpage - which is worrying, given that quishing emails are much harder to identify even by operational detectors. We also find that LLMs can be very good "social engineers": in one company, over 30% of the emails opened led to visiting the landing webpage - a rate exceeding some prior benchmarks. Finally, we complement our study by conducting a survey across the organizations' employees, measuring their "perceived"phishing awareness. Our findings suggest a correlation between higher self-reported awareness and organizational resilience to phishing attempts.
Marie Weinz, Nicola Zannone, Luca Allodi, Giovanni Apruzzese
AsiaCCS2
2025 Towards Explainable Access Control [BlueSky Paper]
abstract
Access control (AC) systems play an important role in ensuring security by regulating how resources are accessed, protecting sensitive information, and maintaining system integrity. Their complexity arises not only from diverse policies and mechanisms but also from the involvement of multiple stakeholders, including resource owners, administrators, and end-users. Taking inspiration from explainable AI and explainable security, we define the first model of access control explainability, as a quality measure of the explanation graph constructed around the decisions made within the AC system. We then explore the literature to identify how existing work can be integrated as explanatory processes. Finally, we leverage our framework to articulate three open research challenges: the collection and interpretation of AC decisions, the effective construction of AC explanation graphs, and the definition of meaningful and computationally efficient explanation quality metrics.
Gelareh Hasel Mehri, Charles Morisset, Nicola Zannone
SACMAT3
2025 Cyberattacks and defenses for Autonomous Navigation Systems: A systematic literature review
abstract
Autonomous Navigation Systems (ANSs) are revolutionizing transportation and logistics by enhancing operational efficiency and reshaping industry standards. However, the absence of human intervention during operational failures makes ANSs more vulnerable to cyberattacks and their consequences. Although prior research has addressed the security challenges of ANSs and proposed various defenses to prevent and mitigate cyberattacks against ANSs, we still lack a comprehensive understanding of the ANS attack surface and the effectiveness of both attacks and defenses. To address this gap, we conduct a systematic review of 125 articles on cybersecurity for ANSs, focusing on their domain, characteristics, and the attack and defense strategies studied in the literature. Our analysis reveals notable research trends, open gaps, and areas for future investigation. Security research on navigation functions remains limited, despite their central role and the risks associated with their compromise. Moreover, our analysis reveals a lack of cross-domain research, resulting in threats and defenses analyzed for one domain being overlooked in others. Finally, we identify discrepancies between attacks and defenses studied in the literature, with a disproportionate focus on defense strategies.
Jorrit Olthuis, Savio Sciancalepore, Nicola Zannone
Comput. Networks3
2025 Securing dependencies: A comprehensive study of Dependabot's impact on vulnerability mitigation
abstract
Abstract The growing use of third-party libraries in software development poses a hidden security risk, as vulnerabilities in these libraries can easily spread to dependent applications. Project maintainers must remain vigilant regarding updates and patches for these external libraries, a responsibility that is facilitated by automated tools, also known as bots . This study centers on Dependabot, a widely adopted bot that offers security and version updates. We aim to scrutinize the impact of Dependabot on mitigating vulnerabilities arising from dependencies, preventing potential prolonged security issues in open-source software. We investigate how developers react to security updates provided by Dependabot within engineered and actively maintained JavaScript projects. We also delve into how project attributes, including the integration of tests and continuous integration (CI) tools, influence the acceptance rate of security updates. Additionally, we perform a detailed analysis of the lifespan of each vulnerability to demonstrate how they are dealt with when Dependabot is in use. Our findings reveal a significant reliance on Dependabot by developers for managing security vulnerabilities in dependencies, with most updates being merged swiftly within days. We find that projects equipped with tests and CI tools are more likely to merge security updates. Conversely, when developers opt not to merge a security update, they often manually address the identified vulnerability. This manual approach, however, could span over several months, potentially exposing projects to security risks. Crucially, in many instances, the manual fixes are potentially inspired by earlier security updates, underscoring Dependabot’s pivotal role in safeguarding dependencies.
Hamid Mohayeji, Andrei Agaronian, Eleni Constantinou, Nicola Zannone, Alexander Serebrenik
Empir. Softw. Eng.4
2024 WiP: Enhancing the Comprehension of XACML Policies
abstract
Policy comprehension is crucial for ensuring data protection. Yet, policies written in flexible and expressive languages such as XACML are not easy to comprehend. In this work, we propose a visualization framework to facilitate the comprehension of XACML policies and their evaluation. Our framework shows a tree representation of the XACML policies to be enforced and highlights the contribution of its policy elements to the overall access decision, thus supporting the understanding of how this decision resulted from the interplay between possibly conflicting access requirements. We implemented our visualization framework as an extension to SAFAX, an XACML-based framework that offers authorization as a service.
Gelareh Hasel Mehri, Tien-Dung Le, Bram C. M. Cappers, Jerry den Hartog, Nicola Zannone
SACMAT5
2024 A Bargaining-Game Framework for Multi-Party Access Control
abstract
International audience
Gelareh Hasel Mehri, Benjamin Monmege, Clara Bertolissi, Nicola Zannone
SACMAT4
2024 The applicability of a hybrid framework for automated phishing detection
abstract
Phishing attacks are a critical and escalating cybersecurity threat in the modern digital landscape. As cybercriminals continually adapt their techniques, automated phishing detection systems have become essential for safeguarding Internet users. However, many current systems rely on single-analysis models, making them vulnerable to sophisticated bypass attempts by hackers. This research delves into the potential of hybrid approaches, which combine multiple models to enhance both the robustness and effectiveness of phishing detection. It highlights existing hybrid models' limitations that focus primarily on effectiveness while ignoring broader applicability. To address these gaps, we introduce a novel framework explicitly designed for applicability in the real world, which poses the foundation for practical and robust phishing detection architectures. We develop a proof of concept to evaluate its effectiveness, robustness, and detection speed. Additionally, we introduce an innovative methodology for simulating bypass attacks on single-analysis base models. Our experiments demonstrate that the proposed hybrid framework outperforms individual models, displaying higher effectiveness, robustness against bypassing attempts, and real-time detection capabilities. Our proof of concept achieves an accuracy of 97.44% thereby outperforming the current state-of-the-art approach while requiring less computational time. The results provide insights into the multifaceted factors of hybrid models, extending beyond mere effectiveness, and emphasize the importance of holistic applicability in hybrid approaches to address the critical need for robust defenses against phishing attacks.
R. J. van Geest, Giuseppe Cascavilla, Joris Hulstijn, Nicola Zannone
Comput. Secur.4
2024 Understanding the stumbling blocks of Italian higher education system: A process mining approach
abstract
Nowadays universities strive to continuously enhance their educational programs to improve both the quality and quantity of their graduates. This is a sensitive problem, especially for Italian universities where only 30% of the students enrolled at the university succeed in graduating within a year after the normal duration of the study plan. Over the last few years, the Italian Ministry of University and Education has introduced several indicators to assess students’ careers and help universities identify possible criticality in their study programs. However, these indicators only provide a high-level overview of the graduation process without providing insights into students’ failure. To address this issue, in this work, we propose to model a study program as a process and exploit process analysis techniques to assess students’ performance. These techniques allow delving into students’ careers, thus enabling the investigation of their failures and delays. The findings obtained by applying our approach to the Bachelor program of an Italian university allowed us to determine common bottlenecks that seem to have an impact on students’ graduation time. Moreover, we were able to determine and compare the career paths of successful and late students. The insights gathered by our analysis can be used to support university personnel in delving into factors causing some exams to be a bottleneck, as well as to determine potential improvements in the overall curricula.
Claudia Diamantini, Laura Genga, Alex Mircoli, Domenico Potena, Nicola Zannone
Expert Syst. Appl.5
2024 Cognition in Social Engineering Empirical Research: A Systematic Literature Review
abstract
The interdisciplinarity of the Social Engineering (SE) domain creates crucial challenges for the development and advancement of empirical SE research, making it particularly difficult to identify the space of open research questions that can be addressed empirically. This space encompasses questions on attack conditions, employed experimental methods, and interactions with underlying cognitive aspects. As a consequence, much potential in the breadth of existing empirical SE research and in its mapping to the actual cognitive processes it aims to measure is left untapped. In this work, we carry out a systematic review of 169 articles investigating overall 735 hypotheses in the field of empirical SE research, focusing on experimental characteristics and core cognitive features from both attacker and target perspectives. Our study reveals that experiments only partially reproduce real attacks and that the exploitable SE attack surface appears much larger than the coverage provided by the current body of research. Factors such as targets’ context and cognitive processes are often ignored or not explicitly considered in experimental designs. Similarly, the effects of different pretexts and varied targetization levels are overall marginally investigated. Our findings on current SE research dynamics provide insights into methodological shortcomings and help identify supplementary techniques that can open promising future research directions.
Pavlo Burda, Luca Allodi, Nicola Zannone
ACM Trans. Comput. Hum. Interact.3
2023 Towards Obfuscation of Programmable Logic Controllers
abstract
Recently published scan data on Shodan shows how 105K Industrial Control Systems (ICSs) around the world are directly accessible from the Internet. In particular, highly sensitive components, such as Programmable Logic Controllers (PLCs), are potentially accessible to attackers who can implement several kinds of attacks. On the other hand, to accomplish non-trivial cyber-physical attacks the attacker must possess a sufficient degree of process comprehension on the physical processes within the target ICS.
Vittoria Cozza, Mila Dalla Preda, Marco Lucchese, Massimo Merro, Nicola Zannone
ARES5
2023 HoneyICS: A High-interaction Physics-aware Honeynet for Industrial Control Systems
abstract
Industrial control systems (ICSs) are vulnerable to cyber-physical attacks, i.e., security breaches in cyberspace that adversely affect the underlying physical processes. In this context, honeypots are effective countermeasures both to defend against such attacks and discover new attack strategies. In recent years, honeypots for ICSs have made significant progress in faithfully emulating OT networks, including physical process interactions. We propose HoneyICS, a high-interaction, physics-aware, scalable, and extensible honeynet for ICSs, equipped with an advanced monitoring system. We deployed our honeynet on the Internet and conducted experiments to evaluate the effectiveness of HoneyICS.
Marco Lucchese, Francesco Lupia, Massimo Merro, Federica Paci, Nicola Zannone, Angelo Furfaro
ARES5
2023 Mitigating Privilege Misuse in Access Control through Anomaly Detection
abstract
Access control is a fundamental component of IT systems to guarantee the confidentiality and integrity of sensitive resources. However, access control systems have inherent limitations: once permissions have been assigned to users, access control systems do not provide any means to prevent users from misusing such permissions. The problem of privilege misuse is typically addressed by employing auditing mechanisms, which verify users’ activities a posteriori. However, auditing does not allow for the timely detection and mitigation of privilege misuse. In this work, we propose a framework that complements access control with anomaly detection for the run-time monitoring of access requests and raises an alert when a user diverges from her normal access behavior. To detect anomalous access requests, we propose a novel approach to build user profiles by eliciting patterns of typical access behavior from historical access data. We evaluated our framework using the access log of a hospital. The results show that our framework has very few false positives and can detect several attack scenarios.
Gelareh Hasel Mehri, Inez L. Wester, Federica Paci, Nicola Zannone
ARES4
2023 A Comprehensive Study on Third-Party User Tracking in Mobile Applications
abstract
Third-party tracking is becoming a prevalent practice in mobile app ecosystems. While providing benefits for app developers, this practice also introduces several privacy issues for end-users. The European General Data Protection Regulation (GDPR) and the ePrivacy Directive (ePD) mandate that mobile apps must obtain user consent before sharing users’ personal data with third-party trackers. This work presents an empirical study investigating the compliance of 400 popular mobile apps (200 Android apps and their corresponding version for iOS) with the ePD and GDPR requirements on valid consent. Moreover, we determined whether these mobile apps actually enforce the consent given by users on being tracked and which are the more common third-party tracker domains contacted by the apps. The analysis shows that none of the studied apps fully comply with ePD and GDPR requirements on valid consent. The most common violations were associated with the principles of freely-given, specific, and revocable consent. Moreover, we found that almost half of the analyzed apps contact third-party tracker domains even when the user has not given their consent to be tracked.
Federica Paci, Jacopo Pizzoli, Nicola Zannone
ARES3
2023 ICS Honeypot Interactions: A Latitudinal Study
abstract
The recent proliferation of sophisticated threats targeting the plant of Industrial Control Systems (ICSs) has triggered a growing interest in the development of dedicated honeypots/honeynets in which the emulation of Operational Technology (OT) components plays a major role. This work presents a latitudinal study on a dataset comprising both IT and ICS interactions collected from an instance of an ICS honeynet emulating ICS devices exposed on the Internet for three months. The study focuses on three orthogonal aspects of such interactions: level of interaction, origin of interactions, and interaction/attack patterns. Our results shed light on the impact of different choices in the configuration of a honeynet on its attractiveness and on the captured behavior.
Francesco Lupia, Marco Lucchese, Massimo Merro, Nicola Zannone
IEEE Big Data4
2023 The Influence of Human Factors on the Intention to Report Phishing Emails
abstract
Phishing attacks are a main threat to organizations and individuals. Current widespread defenses based on spam filters and domain blacklisting are unfortunately insufficient. Prior work identifies phishing reporting as a key, largely untapped resource to mitigate phishing threats. Yet, its practice suffers from very low reporting rates and generally too low an uptake from users. Whereas it is known that phishing reporting behavior is affected by a number of ‘human factors’, a comprehensive view of the different theories and their effects on (intent to) report is not yet developed. To address this gap, we evaluate theories and factors analyzed in the extant literature, build a cohesive theoretical view of their effects and constructs, and develop, model, and empirically evaluate (by means of an online questionnaire, n=284) the resulting hypothesis structure. We discuss both theoretical implications of our findings and research directions for practice at a research and organizational level.
Ioana Andreea Marin, Pavlo Burda, Nicola Zannone, Luca Allodi
CHI3
2023 Impact Analysis of Coordinated Cyber-Physical Attacks via Statistical Model Checking: A Case Study
Ruggero Lanotte, Massimo Merro, Nicola Zannone
FORTE3
2023 Investigating the Resolution of Vulnerable Dependencies with Dependabot Security Updates
abstract
Modern software development practices increasingly rely on third-party libraries due to the inherent benefits of reuse. However, libraries may contain security vulnerabilities that can propagate to the dependent applications. To counter this, maintainers of dependent projects should monitor their dependencies and security reports to ensure that only patched releases of the upstream applications are in use. As manual maintenance of dependencies has shown to be ineffective, several automated tools (aka bots) have been proposed to assist developers in rapidly identifying and resolving vulnerable dependencies. In this work, we focus on Dependabot, a popular bot providing security and version updates, and study developers’ receptivity to its security updates in engineered and actively maintained JavaScript projects. Moreover, we carry out a fine-grained analysis of the lifecycle of every vulnerability to manifest how they are dealt with in the presence of Dependabot. Our findings show that the task of fixing vulnerable dependencies is, to a large extent, delegated to Dependabot and that developers merge the majority of security updates within several days. On the other hand, when developers do not merge a security update, they usually address the identified vulnerability manually. This approach, however, often takes up to several months which in turn could expose the projects to security issues.
Hamid Mohayeji, Andrei Agaronian, Eleni Constantinou, Nicola Zannone, Alexander Serebrenik
MSR4
2023 Data Sharing in Social Networks
abstract
In the context of multi-user cooperative systems and, in particular, in social networks, personal data is uploaded to user profiles and shared with other users. These data are often jointly owned and associated with different degrees of sensitivity according to the users. Controlling access to such multi-owner data, under the authority of different users, is challenging. Traditional access control policies are not expressive enough to determine whether a data disclosure meets the privacy expectations of the different involved parties. In this work, we propose a fine-grained access control model for multi-user cooperative systems and apply it to the context of social networks. We consider compound objects and extend attribute-based access control with provenance information to specify additional access control constraints. We also present a prototype implementation and provide an experimental evaluation to demonstrate the feasibility of the proposed model.
Clara Bertolissi, Alba Martinez Anton, Nicola Zannone
SACMAT3
2023 Privacy-Preserving Multi-Party Access Control for Third-Party UAV Services
abstract
Third-Party Unmanned Aerial Vehicle (UAV) Services, a.k.a. Drone-as-a-Service (DaaS), are an increasingly adopted business model, which enables possibly unskilled users, with no background knowledge, to operate drones and run automated drone-based tasks. Although these services provide significant advantages, the resources provided by drones are typically owned by multiple parties. Thus, Third-Party UAV services require adopting multi-party access control solutions. In this context, the leakage of the access control policies specified by the data owners might disclose confidential information and, thus, they should be protected as well. In this work, we propose a privacy-preserving multi-party access control solution tailored to the application scenarios of Third-Party UAV Services. Our solution advances an existing privacy-preserving multi-party access control framework based on Secure Function Evaluation to fit the distributed and heterogeneous nature of drone deployments. Through an extensive experimental evaluation, we demonstrate our solution can perform private policy evaluation on constrained devices in a reasonable time while requiring limited communication, memory, and energy overhead.
Dominik Roy George, Savio Sciancalepore, Nicola Zannone
SACMAT3
2023 BC-FL k-means: A Blockchain-based Framework for Federated Clustering
abstract
This work presents a novel framework to train clustering models collaboratively without compromising accuracy while accommodating privacy and security in a decentralized manner. Our decentralized collaborative learning model removes the single point of failure and excludes unreliable input by designing a committee-based consensus method in a blockchain-based federated learning, which is equipped with a reputation system. We present a prototype implementation of our approach and show that its performance is comparable with centralized clustering regardless of the distribution of data among devices.
Mina Alishahi, Wouter Leeuw, Nicola Zannone
TrustCom3
2022 ReLOG: A Unified Framework for Relationship-Based Access Control over Graph Databases
Stanley Clark, Nikolay Yakovets, George Fletcher 0001, Nicola Zannone
DBSec4
2022 Poster: A Flexible Relationship-Based Access Control Policy Generator
abstract
A plethora of Relationship-Based Access Control (ReBAC) models have been proposed, varying in the types of policies they can express. This fragmentation has stifled the creation of a benchmark to directly compare the performance of ReBAC systems based on their common supported policies. To solve this problem, we propose RACON, a schema-driven, customisable ReBAC policy generator. RACON generates policies in an intermediate language subsuming the features required to encode existing ReBAC models. This language can subsequently be translated to popular ReBAC policy languages through an extensible translation module. Taking a view of ReBAC policies as graph queries, we implement translations into two popular graph query languages, namely Cypher and SPARQL.
Stanley Clark, Nikolay Yakovets, George Fletcher 0001, Nicola Zannone
SACMAT4
2022 A decision-support framework for data anonymization with application to machine learning processes
Loredana Caruccio, Domenico Desiato, Giuseppe Polese, Genny Tortora, Nicola Zannone
Inf. Sci.5
2021 Combining Text and Visual Features to Improve the Identification of Cloned Webpages for Early Phishing Detection
abstract
Phishing attacks arrive in high numbers and often spread quickly, meaning that after-the-fact countermeasures such as domain blacklisting are limited in efficacy. Visual similarity-based approaches have the potential of detecting previously unseen phishing webpages. These approaches, however, require identifying the legitimate webpage(s) they reproduce. Existing approaches rely on textual feature analysis for target identification, with misclassification rates of approximately 1%; however, as most websites a user might visit are legitimate, additional research is needed to further reduce classification errors. In this work, we propose a novel method for target identification that relies on both visual features (extracted from a screenshot of the web page) and textual features (extracted from the DOM of the web page) to identify which website a phishing web page is replicating, and assess its effectiveness in detecting phishing websites using data from phishing aggregators such as OpenPhish, PhishTank and PhishStats. Compared to state-of-the-art text-based classifiers, our method reduces the phishing misclassification rate by 67% (from 1.02% to 0.34%), for an accuracy of 99.66%. This work provides a further step forwards toward semi-automated decision support systems for phishing detection.
Bram van Dooremaal, Pavlo Burda, Luca Allodi, Nicola Zannone
ARES4
2021 Not a Free Lunch, But a Cheap One: On Classifiers Performance on Anonymized Datasets
Mina Alishahi, Nicola Zannone
DBSec2
2021 Comparing Classifiers' Performance under Differential Privacy
abstract
The application of differential privacy in privacy-preserving data analysis has gained momentum in recent years. In particular, it provides an effective solution for the construction of privacy-preserving classifiers, in which one party owns the data and another party is interested in obtaining a classifier model from this data. While several approaches have been proposed in the literature to employ differential privacy for the construction of classifiers, an understanding of the difference in performance of these classifiers is currently missing. This knowledge enables the data owner and the analyst to select the most appropriate classification algorithm and training parameters in order to guarantee high privacy requirements while minimizing the loss of accuracy. In this study, we investigate the impact of the use of differential privacy on three well-known classifiers, i.e., Naïve Bayes, SVM, and Decision Tree classifiers. To this end, we show how these classifiers can be trained in a differential privacy setting and perform extensive experiments to evaluate the effect of this privacy enforcement on their performance.
Milan Lopuhaä-Zwakenberg, Mina Alishahi, Jeroen Kivits, Jordi Klarenbeek, Gert-Jan van der Velde, Nicola Zannone
SECRYPT6
2021 Privacy-preserving policy evaluation in multi-party access control
abstract
Recent years have seen an increasing popularity of online collaborative systems like social networks and web-based collaboration platforms. Collaborative systems typically offer their users a digital environment in which they can work together and share resources and information. These resources and information might be sensitive and, thus, they should be protected from unauthorized accesses. Multi-party access control is emerging as a new paradigm for the protection of co-owned and co-managed resources, where the policies of all users involved in the management of a resource should be accounted for collaborative decision making. Existing approaches, however, only focus on the jointly protection of resources and do not address the protection of the individual user policies themselves, whose disclosure might leak sensitive information. In this work, we propose a privacy-preserving mechanism for the evaluation of multi-party access control policies, which preserves the confidentiality of user policies while remaining capable of making collaborative decisions. To this end, we design secure computation protocols for the evaluation of policies in protected form against an access query and realize such protocols using two privacy-preserving techniques, namely Homomorphic Encryption and Secure Functional Evaluation. We show the practical feasibility of our mechanism in terms of computation and communication costs through an experimental evaluation.
Mina Alishahi, Ischa Stork, Nicola Zannone
J. Comput. Secur.3
2020 Testing the effectiveness of tailored phishing techniques in industry and academia: a field experiment
abstract
Organizations are experiencing more and more sophisticated attacks specifically targeting their employees and customers. These attacks exploit tailored information on the victim or organization to increase their credibility. To date, no study has evaluated the role of 'traditional' phishing cognitive effects in these advanced settings. In this paper, we run a field experiment targeting 747 subjects employed in two organizations (a university and a large international consultancy company) to evaluate the interaction between phishing persuasion techniques and the success rate in a highly-tailored setting. For this purpose, we exploit well-established user notification methods to devise enhanced attack delivery techniques, and evaluate how such techniques affect success rate of our phishing campaigns. We find that the effect of 'traditional' attack techniques is widely mitigated in highly-tailored phishing settings, suggesting that current user training and detection techniques may be off-target for more sophisticated attacks. However, we find that the means by which the attack is delivered to the victim matter, and can greatly (up to three times) boost the effect of the base attack.
Pavlo Burda, Tzouliano Chotza, Luca Allodi, Nicola Zannone
ARES4
2020 SoK: engineering privacy-aware high-tech systems
abstract
The processing of personal data is becoming a key business factor, especially for high-tech system industries such as automotive and healthcare service providers. To protect such data, the European Union (EU) has introduced the General Data Protection Regulation (GDPR), with the aim to standardize and strengthen data protection policies across EU countries. The GDPR defines stringent requirements on the collection and processing of personal data and imposes severe fines and penalties on data controllers and processors for non-compliance. Although the GDPR is enforce since 2018, many public and private organizations are still struggling to fully comply with the regulation. A main reason for this is the lack of usable methodologies that can support developers in designing of GDPR-complaint high-tech systems. This paper examines the growing literature on methodologies for the design of privacy-aware systems, and identifies the main challenges to be addressed in order to facilitate developers in the design of such systems. In particular, we investigate to what extent existing methodologies (i) cover GDPR and privacy-by-design principles, (ii) address different levels of system design concerns, and (iii) have demonstrated their suitability for the purpose. Our literature study shows that the domain landscape appears to be heterogeneous and disconnected, as existing methodologies often focus only on subsets of the GDPR principles and/or on specific angles of system design. Based on our findings, we provide recommendations on the definition of comprehensive methodologies tailored to designing GDPR-compliant high-tech systems.
Giovanni Maria Riva, Alexandr Vasenev, Nicola Zannone
ARES3
2020 Predictive Analytics to Prevent Voice over IP International Revenue Sharing Fraud
Yoram J. Meijaard, Bram C. M. Cappers, Josh Mengerink, Nicola Zannone
DBSec4
2020 On the Comparison of Classifiers' Construction over Private Inputs
abstract
Classifiers are often trained over data collected from different sources. Sharing their data with other entities, however, can raise privacy concerns for data owners. To protect data confidentiality while being able to train a classifier, effective solutions have been proposed in the literature to construct various types of classifiers over private data. However, to date an analysis and comparison of the computation and communication costs for the construction of classifiers over private data is missing, making it difficult to determine which classifier can be used in a given application domain. In this work, we show how two well-known classifiers (Naive Bayes and SVM classifiers) can be securely build over private inputs, and evaluate their construction costs. We assess the computation and communication costs for training the classifiers both theoretically and empirically for different benchmark datasets.
Mina Alishahi, Nicola Zannone
TrustCom2
2020 Privacy Preserving Statistical Detection of Adversarial Instances
abstract
Adversarial instances are malicious input designed by attackers to cause a classification model to make a false prediction, e.g. in Spam detection. Effective solutions have been proposed to detect and block adversarial instances in real time. Still, the proposed approaches fail to detect adversarial instances over private input (required by many on-line platforms analyzing sensitive personal data). In this work, we propose a novel framework that applies a statistical test to detect adversarial instances when data under analysis are in private format. The practical feasibility of our approach in terms of computation cost is shown through an experimental evaluation.
Mina Alishahi, Nicola Zannone
WETICE2
2020 A survey on multi-factor authentication for online banking in the wild
Federico Sinigaglia, Roberto Carbone, Gabriele Costa 0001, Nicola Zannone
Comput. Secur.4
2019 Unveiling Systematic Biases in Decisional Processes: An Application to Discrimination Discovery
abstract
Decisional processes are at the basis of several security and privacy applications. However, they are often not transparent and can be affected by human or algorithmic biases that may lead to systematically misleading or unfair outcomes. To unveil these biases, one has to identify which information was used to make the decision and to quantify to what extent such information has influenced the process outcome. Two classes of techniques are widely used to determine possible correlation between variables within decisional processes from observational data: (i) econometric techniques, in particular regression analysis, and (ii) knowledge discovery techniques, in particular association rules mining. However, these techniques, taken individually, have intrinsic drawbacks that limit their applicability. In this work, we propose an approach for unveiling biases in decisional processes, which leverages association rule mining for systematic hypothesis generation and regression analysis for model selection and recommendation extraction. We demonstrate the proposed approach in the context of discrimination detection, showing that not only it provides 'statistically significant' evidence of discrimination but it also allows for a more efficient operationalization of the recommendations extracted, upon which the decision maker can operate.
Laura Genga, Luca Allodi, Nicola Zannone
AsiaCCS3
2019 Using Provenance for Secure Data Fusion in Cooperative Systems
abstract
In the context of cooperative systems, data coming from multiple, autonomous, heterogeneous information sources, is processed and fused into new pieces of information that can be further processed by other entities participating in the cooperation. Controlling the access to such evolving and variegated data, often under the authority of different entities, is challenging. In this work, we identify a set of access control requirements for multi-source cooperative systems and propose an attribute-based access control model where provenance information is used to specify access constraints that account for both the evolution of data objects and the process of data fusion. We demonstrate the feasibility of the proposed model by showing how it can be implemented within existing access control mechanisms with minimal changes.
Clara Bertolissi, Jerry den Hartog, Nicola Zannone
SACMAT3
2019 Discovering reliable evidence of data misuse by exploiting rule redundancy
Laura Genga, Nicola Zannone, Anna Cinzia Squicciarini
Comput. Secur.2
2019 A framework for the extended evaluation of ABAC policies
abstract
A main challenge of attribute-based access control (ABAC) is the handling of missing information. Several studies have shown that the way standard ABAC mechanisms, e.g. based on XACML, handle missing information is flawed, making ABAC policies vulnerable to attribute-hiding attacks. Recent work has addressed the problem of missing information in ABAC by introducing the notion of extended evaluation, where the evaluation of a query considers all queries that can be obtained by extending the initial query. This method counters attribute-hiding attacks, but a naïve implementation is intractable, as it requires an evaluation of the whole query space. In this paper, we present a framework for the extended evaluation of ABAC policies. The framework relies on Binary Decision Diagram (BDDs) data structures for the efficient computation of the extended evaluation of ABAC policies. We also introduce the notion of query constraints and attribute value power to avoid evaluating queries that do not represent a valid state of the system and to identify which attribute values should be considered in the computation of the extended evaluation, respectively. We illustrate our framework using three real-world policies, which would be intractable with the original method but which are analyzed in seconds using our framework.
Charles Morisset, Tim A. C. Willemse, Nicola Zannone
Cybersecur.3
2019 Access control in Internet-of-Things: A survey
Sowmya Ravidas, Alexios Lekidis, Federica Paci, Nicola Zannone
J. Netw. Comput. Appl.4
2018 Towards Adaptive Access Control
Luciano Argento, Andrea Margheri, Federica Paci, Vladimiro Sassone, Nicola Zannone
DBSec5
2018 Economic incentives on DNSSEC deployment: Time to move from quantity to quality
abstract
The security extensions to the DNS (DNSSEC) currently cover approximately 3% of all domains worldwide. In response to the low deployment of DNSSEC, a few top-level domains started offering 'per-domain' economic incentives to encourage adoption of the protocol by offering a yearly discount on each signed domain. However, it remains unclear whether these incentives are well-balanced and foster the overall security of the infrastructure as well as its deployment at scale. In this paper we argue that, in the presence of fixed costs of deployment, misaligned 'per-domain' incentives may have the collateral effect of encouraging large operators to massively deploy unsecure implementations of DNSSEC, whereas smaller operators, for which the effect of the economic incentive is negligible, may not significantly benefit from it. To investigate this, we study the security of DNSSEC deployment at scale, particularly in TLDs that offer economic incentives. We find that the security of DNSSEC implementations in the wild poorly reflects standard recommendations, particularly for tasks that cannot be solved by triggering a flag in the DNS software service (e.g. key rollover). Further, we find that, on average, large operators deploy weak DNSSEC security more frequently than small DNSSEC operators, suggesting that current incentives are ineffective in promoting a secure adoption and in deterring insecure implementations. We conclude the paper with actionable recommendations for TLD registry operators to improve the alignment of economic incentives with secure DNSSEC requirements.
Tho Le, Roland van Rijswijk-Deij, Luca Allodi, Nicola Zannone
NOMS4
2018 A Lazy Approach to Access Control as a Service (ACaaS) for IoT: An AWS Case Study
abstract
The Internet of Things (IoT) is receiving considerable attention from both industry and academia because of the new business models that it enables and the new security and privacy challenges that it generates. Major Cloud Service Providers (CSPs) have proposed platforms to support IoT by combining cloud and edge computing. However, the security mechanisms available in the cloud have been extended to IoT with some shortcomings with respect to the management and enforcement of access control policies. Access Control as a Service (ACaaS) is emerging as a solution to overcome these difficulties. The paper proposes a lazy approach to ACaaS that allows the specification and management of policies independently of the CSP while leveraging its enforcement mechanisms. We demonstrate the approach by investigating (also experimentally) alternative deployments in the IoT platform offered by Amazon Web Services on a realistic smart lock solution.
Tahir Ahmad, Umberto Morelli, Silvio Ranise, Nicola Zannone
SACMAT4
2018 Efficient Extended ABAC Evaluation
abstract
A main challenge of attribute-based access control (ABAC) is the handling of missing information. Several studies show that the way standard ABAC mechanisms (e.g., XACML) handle missing information is flawed, making ABAC policies vulnerable to attribute-hiding attacks. Recent work addressed the problem of missing information in ABAC by introducing the notion of extended evaluation, where the evaluation of a query considers all possible ways of extending that query. This method counters attribute-hiding attacks, but a naive implementation is intractable, as it requires an evaluation of the whole query space. In this paper, we present an efficient extended ABAC evaluation method that relies on the encoding of ABAC policies as multiple Binary Decision Diagrams (BDDs), and on the specification of query constraints to avoid including the evaluation of queries that do not represent a valid state of the system. We illustrate our approach on two real-world case studies, which would be intractable with the original method and are analyzed in seconds with our method.
Charles Morisset, Tim A. C. Willemse, Nicola Zannone
SACMAT3
2018 Multi-Party Access Control: Requirements, State of the Art and Open Challenges
abstract
Multi-party access control is gaining attention and prominence within the community, as access control models and systems are faced with complex, jointly-owned and jointly-managed content. Traditional single-user approaches lack the richness and flexibility to accommodate these scenarios, resulting in undesired disclosure of sensitive data and resources. Moving forward fundamental work in this area is critical. In particular, as personal data amasses and algorithms for data mining improve, personally identifiable information is more readily inferred and the practical implications of privacy decisions are relatively opaque. This is true even at the individual level, but the parallel problem for jointly managed content involves the cross product of these complex outcomes. In this presentation, we discuss fundamental requirements of successful multi-party access control mechanisms and contextualize these concepts with respect to the state of the art. Based on this analysis, we identify open challenges and draw a roadmap for future work.
Anna Cinzia Squicciarini, Sarah Michele Rajtmajer, Nicola Zannone
SACMAT3
2018 Security and privacy for innovative automotive applications: A survey
Van Huynh Le, Jerry den Hartog, Nicola Zannone
Comput. Commun.3
2018 Linking data and process perspectives for conformance analysis
Mahdi Alizadeh, Xixi Lu 0001, Dirk Fahland, Nicola Zannone, Wil M. P. van der Aalst
Comput. Secur.4
2018 Discovering anomalous frequent patterns from partially ordered event logs
abstract
Conformance checking allows organizations to compare process executions recorded by the IT system against a process model representing the normative behavior. Most of the existing techniques, however, are only able to pinpoint where individual process executions deviate from the normative behavior, without considering neither possible correlations among occurred deviations nor their frequency. Moreover, the actual control-flow of the process is not taken into account in the analysis. Neglecting possible parallelisms among process activities can lead to inaccurate diagnostics; it also poses some challenges in interpreting the results, since deviations occurring in parallel behaviors are often instantiated in different sequential behaviors in different traces. In this work, we present an approach to extract anomalous frequent patterns from historical logging data. The extracted patterns can exhibit parallel behaviors and correlate recurrent deviations that have occurred in possibly different portions of the process, thus providing analysts with a valuable aid for investigating nonconforming behaviors. Our approach has been implemented as a plug-in of the ESub tool and evaluated using both synthetic and real-life logs.
Laura Genga, Mahdi Alizadeh, Domenico Potena, Claudia Diamantini, Nicola Zannone
J. Intell. Inf. Syst.5
2017 Formal analysis of XACML policies using SMT
Fatih Turkmen, Jerry den Hartog, Silvio Ranise, Nicola Zannone
Comput. Secur.4
2016 Role Mining with Missing Values
abstract
Over the years several organizations are migrating to Role-Based Access Control (RBAC) as a practical solution to regulate access to sensitive information. Role mining has been proposed to automatically extract RBAC policies from the current set of permissions assigned to users. Existing role mining approaches usually require that this set of permissions is retrievable and complete. Such an assumption, however, cannot be met in practice as permissions can be hard-coded in the applications or distributed over several subsystems. In those cases, permissions can be obtained from activity logs recording the actions performed by users. This, however, can provide an incomplete representation of the permissions within the system. Thus, existing role mining solutions are not directly applicable. In this work, we study the problem of role mining with incomplete knowledge. In particular, we investigate approaches for two instances of the role mining problem with missing values. Moreover, we study metrics to properly evaluate the obtained RBAC policies. We validate the investigated approaches using both synthetic and real data.
Sokratis Vavilis, Alexandru Ionut Egner, Milan Petkovic, Nicola Zannone
ARES4
2016 Risk-based Analysis of Business Process Executions
abstract
Organizations need to monitor their business processes to ensure that what actually happens in the system is compliant with the prescribed behavior. Deviations from the prescribed behavior may correspond to violations of security requirements and expose organizations to severe risks. Thus, it is crucial for organizations to detect and address nonconforming behavior as early as possible. In this paper, we present an auditing framework that facilitates the analysis of process executions by detecting nonconforming behaviors and ranking them with respect to their criticality. Our framework employs conformance checking techniques to detect possible explanations of nonconformity. Based on such explanations, the framework assesses the criticality of nonconforming process executions based on historical logging data and context information.
Mahdi Alizadeh, Nicola Zannone
CODASPY2
2016 An Authorization Service for Collaborative Situation Awareness
abstract
In international military coalitions, situation awareness is achieved by gathering critical intel from different authorities. Authorities want to retain control over their data, as they are sensitive by nature, and, thus, usually employ their own authorization solutions to regulate access to them. In this paper, we highlight that harmonizing authorization solutions at the coalition level raises many challenges. We demonstrate how we address authorization challenges in the context of a scenario defined by military experts using a prototype implementation of SAFAX, an XACML-based architectural framework tailored to the development of authorization services for distributed systems.
Alexandru Ionut Egner, Duc Luu, Jerry den Hartog, Nicola Zannone
CODASPY4
2016 Data Governance and Transparency for Collaborative Systems
Rauf Mahmudlu, Jerry den Hartog, Nicola Zannone
DBSec3
2016 A severity-based quantification of data leakages in database systems
abstract
The detection and handling of data leakages is becoming a critical issue for organizations. To this end, data leakage solutions are usually employed by organizations to monitor network traffic and the use of portable storage devices. However, these solutions often produce a large number of alerts, whose analysis is time-consuming and costly for organizations. To effectively handle leakage incidents, organizations should be able to focus on the most severe incidents. Therefore, alerts need to be analyzed and prioritized with respect to their severity. This work presents a novel approach for the quantification of data leakages based on their severity. The approach quantifies the severity of leakages with respect to the amount and sensitivity of the leaked information as well as the ability to re-identify the data subjects of the leaked information. To specify and reason on data sensitivity in an application domain, we propose a data model representing the knowledge within the domain. We validate our quantification approach by analyzing data leakages within a healthcare environment. Moreover, we demonstrate that the data model allows for a more accurate characterization of data sensitivity while reducing the efforts for its specification.
Sokratis Vavilis, Milan Petkovic, Nicola Zannone
J. Comput. Secur.3
2015 On Missing Attributes in Access Control: Non-deterministic and Probabilistic Attribute Retrieval
abstract
Attribute Based Access Control (ABAC) is becoming the reference model for the specification and evaluation of access control policies. In ABAC policies and access requests are defined in terms of pairs attribute names/values. The applicability of an ABAC policy to a request is determined by matching the attributes in the request with the attributes in the policy. Some languages supporting ABAC, such as PTaCL or XACML 3.0, take into account the possibility that some attributes values might not be correctly retrieved when the request is evaluated, and use complex decisions, usually describing all possible evaluation outcomes, to account for missing attributes.
Jason Crampton, Charles Morisset, Nicola Zannone
SACMAT3
2015 Preventing Information Inference in Access Control
abstract
Technological innovations like social networks, personal devices and cloud computing, allow users to share and store online a huge amount of personal data. Sharing personal data online raises significant privacy concerns for users, who feel that they do not have full control over their data. A solution often proposed to alleviate users' privacy concerns is to let them specify access control policies that reflect their privacy constraints. However, existing approaches to access control often produce policies which either are too restrictive or allow the leakage of sensitive information. In this paper, we present a novel access control model that reduces the risk of information leakage. The model relies on a data model which encodes the domain knowledge along with the semantic relations between data. We illustrate how the access control model and the reasoning over the data model can be automatically translated in XACML. We evaluate and compare our model with existing access control models with respect to its effectiveness in preventing leakage of sensitive information and efficiency in authoring policies. The evaluation shows that the proposed model allows the definition of effective access control policies that mitigate the risks of inference of sensitive data while reducing users' effort in policy authoring compared to existing models.
Federica Paci, Nicola Zannone
SACMAT2
2015 Pre-Distribution of Certificates for Pseudonymous Broadcast Authentication in VANET
abstract
In the context of vehicular networks, certificate management is challenging because of the dynamic topology and privacy requirements. In this paper we propose a technique that combines certificate omission and certificate pre-distribution in order to reduce communication overhead and to minimize cryptographic packet loss. Simulation results show that this technique is useful to improve awareness quality during pseudonym changes.
Michael Feiri, Rolf Pielage, Jonathan Petit, Nicola Zannone, Frank Kargl
VTC Spring4
2015 An anomaly analysis framework for database systems
Sokratis Vavilis, Alexandru Ionut Egner, Milan Petkovic, Nicola Zannone
Comput. Secur.4
2015 Conviviality-driven access control policy
Donia El Kateb, Nicola Zannone, Assaad Moawad, Patrice Caire, Grégory Nain, Tejeddine Mouelhi, Yves Le Traon
Requir. Eng.2
2014 POSTER: Analyzing Access Control Policies with SMT
abstract
The flexibility and expressiveness of eXtensible Access Control Markup Language (XACML) allows the specification of a wide range of policies in different access control models. However, XACML policies are often verbose and, thus, prone to errors. Several tools have been developed to assist policy authors for the verification and analysis of policies, but most of them are limited in the types of analysis they can perform. In particular, they are not able to reason about predicates of non-boolean variables and, even if they do, they do it inefficiently. In this paper, we present the X2S framework, a formal framework for the analysis of XACML policies that employs Satisfiability Modulo Theories (SMT) as the underlying reasoning mechanism. The use of SMT not only allows more fine-grained analysis of policies, but it also improves the performance of policy analysis significantly.
Fatih Turkmen, Jerry den Hartog, Nicola Zannone
CCS3
2014 Data Leakage Quantification
Sokratis Vavilis, Milan Petkovic, Nicola Zannone
DBSec3
2014 Reduction of access control decisions
abstract
Access control has been proposed as "the" solution to prevent unauthorized accesses to sensitive system resources. Historically, access control models use a two-valued decision set to indicate whether an access should be granted or denied. Many access control models have extended the two-valued decision set to indicate, for instance, whether a policy is applicable to an access query or an error occurred during policy evaluation. Decision sets are often coupled with operators for combining decisions from multiple applicable policies. Although a larger decision set is more expressive, it may be necessary to reduce it to a smaller set in order to simplify the complexity of decision making or enable comparison between access control models. Moreover, some access control mechanisms like XACML~v3 uses more than one decision set. The projection from one decision set to the other may result in a loss of accuracy, which can affect the final access decision. In this paper, we present a formal framework for the analysis and comparison of decision sets centered on the notion of decision reduction. In particular, we introduce the notion of safe reduction, which ensures that a reduction can be performed at any level of policy composition without changing the final decision. We demonstrate the framework by analyzing XACML v3 against the notion of safe reduction. From this analysis, we draw guidelines for the selection of the minimal decision set with respect to a given set of combining operators.
Charles Morisset, Nicola Zannone
SACMAT2
2014 A reference model for reputation systems
Sokratis Vavilis, Milan Petkovic, Nicola Zannone
Decis. Support Syst.3
2014 GEM: A distributed goal evaluation algorithm for trust management
abstract
Abstract Trust management is an approach to access control in distributed systems where access decisions are based on policy statements issued by multiple principals and stored in a distributed manner. In trust management, the policy statements of a principal can refer to other principals' statements; thus, the process of evaluating an access request (i.e., a goal) consists of finding a “chain” of policy statements that allows the access to the requested resource. Most existing goal evaluation algorithms for trust management either rely on a centralized evaluation strategy, which consists of collecting all the relevant policy statements in a single location (and therefore they do not guarantee the confidentiality of intensional policies), or do not detect the termination of the computation (i.e., when all the answers of a goal are computed). In this paper, we present GEM, a distributed goal evaluation algorithm for trust management systems that relies on function-free logic programming for the specification of policy statements. GEM detects termination in a completely distributed way without disclosing intensional policies, thereby preserving their confidentiality. We demonstrate that the algorithm terminates and is sound and complete with respect to the standard semantics for logic programs.
Daniel Trivellato, Nicola Zannone, Sandro Etalle
Theory Pract. Log. Program.2
2013 Data reliability in home healthcare services
abstract
Home healthcare services are emerging as a new frontier in healthcare practices. Data reliability, however, is crucial for the acceptance of these new services. This work presents a semi-automated system to evaluate the quality of medical measurements taken by patients. The system relies on data qualifiers to evaluate various quality aspects of measurements. The overall quality of measurements is determined on the basis of these qualifiers enhanced with a troubleshooting mechanism. Namely, the troubleshooting mechanism guides healthcare professionals in the investigation of the root causes of low quality values.
Sokratis Vavilis, Nicola Zannone, Milan Petkovic
CBMS2
2013 TRIPLEX: verifying data minimisation in communication systems
abstract
Systems dealing with personal information are legally required to satisfy the principle of data minimisation. Privacy-enhancing protocols use cryptographic primitives to minimise the amount of personal information exposed by communication. However, the complexity of these primitives and their interplay makes it hard for non-cryptography experts to understand the privacy implications of their use. In this paper, we present TRIPLEX, a framework for the analysis of data minimisation in privacy-enhancing protocols.
Meilof Veeningen, Mayla Brusò, Jerry den Hartog, Nicola Zannone
CCS4
2013 Privacy-Aware Web Service Composition and Ranking
abstract
Service selection is a key issue in the Future Internet, where applications are built by composing services and content offered by different service providers. Most existing service selection schemas only focus on QoS properties of services such as throughput, latency and response time, or on their trust and reputation level. By contrast, the risk of privacy breaches arising from the selection of component services whose privacy policy is not compliant with customers' privacy preferences is largely ignored. In this paper, we propose a novel privacy-preserving Web service composition and selection approach which (i) makes it possible to verify the compliance between users' privacy requirements and providers' privacy policies and (ii) ranks the composite Web services with respect to the privacy level they offer. We demonstrate our approach using a travel agency Web service as an example of service composition.
Elisa Costante, Federica Paci, Nicola Zannone
ICWS3
2013 Database Anomalous Activities - Detection and Quantification
Elisa Costante, Sokratis Vavilis, Sandro Etalle, Jerry den Hartog, Milan Petkovic, Nicola Zannone
SECRYPT6
2013 A Semantic Security Framework for Systems of Systems
abstract
Systems of systems (SoS) are dynamic coalitions of distributed, autonomous and heterogeneous systems that collaborate to achieve a common goal. While offering several advantages in terms of scalability and flexibility, the SoS paradigm has a strong impact on systems interoperability and on the security requirements of the collaborating parties. In this paper, we introduce a service-oriented security framework that protects the information exchanged among the parties in an SoS, while preserving parties' autonomy and interoperability. Confidentiality and integrity of information are protected by combining context-aware access control with trust management. Autonomy and interoperability among parties are enabled by the use of ontology-based services. More precisely, parties may refer to different ontologies to define the semantics of the terms used in their security policies and to describe domain knowledge and context information; a semantic alignment technique is then employed to map concepts from different ontologies and align the parties' vocabularies. We demonstrate the applicability of our solution by deploying a prototype implementation of the framework in an SoS in the maritime safety and security domain.
Daniel Trivellato, Nicola Zannone, Maurice Glaundrup, Jacek Skowronek, Sandro Etalle
Int. J. Cooperative Inf. Syst.2
2013 Requirements engineering within a large-scale security-oriented research project: lessons learned
abstract
Requirements engineering has been recognized as a fundamental phase of the software engineering process. Nevertheless, the elicitation and analysis of requirements are often left aside in favor of architecture-driven software development. This tendency, however, can lead to issues that may affect the success of a project. This paper presents our experience gained in the elicitation and analysis of requirements in a large-scale security-oriented European research project, which was originally conceived as an architecture-driven project. In particular, we illustrate the challenges that can be faced in large-scale research projects and consider the applicability of existing best practices and off-the-shelf methodologies with respect to the needs of such projects. We then discuss how those practices and methods can be integrated into the requirements engineering process and possibly improved to address the identified challenges. Finally, we summarize the lessons learned from our experience and the benefits that a proper requirements analysis can bring to a project.
Seda Gurses, Magali Seguran, Nicola Zannone
Requir. Eng.3
2012 Enforcing Access Control in Virtual Organizations Using Hierarchical Attribute-Based Encryption
abstract
Virtual organizations are dynamic, interorganizational collaborations that involve systems and services belonging to different security domains. Several solutions have been proposed to guarantee the enforcement of the access control policies protecting the information exchanged in a distributed system, but none of them addresses the dynamicity characterizing virtual organizations. In this paper we propose a dynamic hierarchical attribute-based encryption (D-HABE)scheme that allows the institutions in a virtual organization to encrypt information according to a policy in such a way that only users with appropriate attributes can decrypt it. In addition, we introduce a key management scheme that determines which user is entitled to receive which attribute key from which domain authority.
Muhammad Asim 0007, Tanya Ignatenko, Milan Petkovic, Daniel Trivellato, Nicola Zannone
ARES5
2012 Measuring Privacy Compliance Using Fitness Metrics
Sebastian Banescu, Milan Petkovic, Nicola Zannone
BPM3
2011 Poster: protecting information in systems of systems
Daniel Trivellato, Nicola Zannone, Sandro Etalle
CCS2
2011 Engineering and verifying agent-oriented requirements augmented by business constraints with B-Tropos
abstract
We propose $${\mathcal{B}}$$ -Tropos as a modeling framework to support agent-oriented systems engineering, from high-level requirements elicitation down to execution-level tasks. In particular, we show how $${\mathcal{B}}$$ -Tropos extends the Tropos methodology by means of declarative business constraints, inspired by the ConDec graphical language. We demonstrate the functioning of $${\mathcal{B}}$$ -Tropos using a running example inspired by a real-world industrial scenario, and we describe how $${\mathcal{B}}$$ -Tropos models can be automatically formalized in computational logic, discussing formal properties of the resulting framework and its verification capabilities.
Marco Montali, Paolo Torroni, Nicola Zannone, Paola Mello, Volha Bryl
Auton. Agents Multi Agent Syst.3
2010 Towards Data Protection Compliance
Nicola Zannone, Milan Petkovic, Sandro Etalle
SECRYPT1
2010 A vulnerability-centric requirements engineering framework: analyzing security attacks, countermeasures, and requirements based on vulnerabilities
Golnaz Elahi, Eric S. K. Yu, Nicola Zannone
Requir. Eng.3
2009 A Modeling Ontology for Integrating Vulnerabilities into Security Requirements Conceptual Foundations
Golnaz Elahi, Eric S. K. Yu, Nicola Zannone
ER3
2009 The Si* Modeling Framework: Metamodel and Applications
abstract
Security Requirements Engineering is emerging spurred by the realization that security must be dealt from the early phases of the system development process. Modeling languages in this field are challenging as they must provide concepts appropriate in order to talk about security within an organization. In previous work we introduced the SI* modeling language tailored to capture security aspects of socio-technical systems. SI* is founded on four main notions, namely supervision, permission, delegation, and trust. In this paper, we present the SI* metamodel. We also present some frameworks and methodologies founded on this modeling language for the analysis of security and dependability requirements as well as the exploration of design alternatives and the generation of skeletons of secure business processes. The paper also presents a development environment that uses the SI* metamodel as its basis core.
Nicola Zannone
Int. J. Softw. Eng. Knowl. Eng.1
2009 Towards the development of privacy-aware systems
Paolo Guarda, Nicola Zannone
Inf. Softw. Technol.2
2008 Risk as Dependability Metrics for the Evaluation of Business Solutions: A Model-driven Approach
abstract
The analysis of business solutions is one of critical issues in industry. Risk is one of the most preeminent and accepted metrics for the evaluation of business solutions. Not surprisingly, many research efforts have been devoted to develop risk management frameworks. Among them, Tropos Goal-Risk offers a formal framework for assessing and treating risks on the basis of the likelihood and severity of failures. In this paper, we extend the Tropos Goal-Risk to assess and treat risks by considering the interdependency among actors within an organization. To make the discussion more concrete, we apply the proposed framework for analysis of the risks within manufacturing organizations.
Yudistira Asnar, Rocco Moretti, Maurizio Sebastianis, Nicola Zannone
ARES4
2008 Formal Analysis of BPMN Via a Translation into COWS
Davide Prandi, Paola Quaglia, Nicola Zannone
COORDINATION3
2008 Requirements model generation to support requirements elicitation: the Secure Tropos experience
Nadzeya Kiyavitskaya, Nicola Zannone
Autom. Softw. Eng.2
2007 From Trust to Dependability through Risk Analysis
abstract
The importance of critical systems has been widely recognized and several efforts are devoted to integrate dependability requirements in their development process. Such efforts result in a number of models, frameworks, and methodologies that have been proposed to model and assess the dependability of critical systems. Among them, risk analysis considers the likelihood and severity of failures for evaluating the risk affecting the system. In our previous work, we introduced the Tropos goal-risk framework, a formal framework for modeling, assessing, and treating risks on the basis of the likelihood and severity of failures. In this paper, we refine this framework introducing the notion of trust for assessing risks on the basis of the organizational setting of the system. The assessment process is also enhanced to analyze risks along trust relations among actors. To make the discussion more concrete, we illustrate the framework with a case study on partial airspace delegation in air traffic management system
Yudistira Asnar, Paolo Giorgini, Fabio Massacci, Nicola Zannone
ARES4
2007 How to capture, model, and verify the knowledge of legal, security, and privacy experts: a pattern-based approach
abstract
Laws set requirements that force organizations to assess the security and privacy of their IT systems and impose the adoption of the implementation of minimal precautionary security measures. Several frameworks have been proposed to deal with thii issue. For instance, purpose-based access control is normally considered a good solution for meeting the requirements of privacy legislation. Yet, understanding why, how, and when such solutions to security and privacy problems have to be deployed is often unanswered.
Luca Compagna, Paul El Khoury, Fabio Massacci, Reshma Thomas, Nicola Zannone
ICAIL5
2007 Computer-aided Support for Secure Tropos
Fabio Massacci, John Mylopoulos, Nicola Zannone
Autom. Softw. Eng.3
2007 From Hippocratic Databases to Secure Tropos: a Computer-Aided Re-Engineering Approach
abstract
Privacy protection is a growing concern in the marketplace. Yet, privacy requirements and mechanisms are usually retro-fitted into a pre-existing design which may not be able to accommodate them due to potential conflicts with functional requirements. We propose a procedure for automatically extracting privacy requirements from databases supporting access control mechanisms for personal data (hereafter Hippocratic databases) and representing them in the Secure Tropos framework where tools are available for checking the correctness and consistency of privacy requirements. The procedure is illustrated with a case study.
Fabio Massacci, John Mylopoulos, Nicola Zannone
Int. J. Softw. Eng. Knowl. Eng.3
2006 Designing Security Requirements Models Through Planning
Volha Bryl, Fabio Massacci, John Mylopoulos, Nicola Zannone
CAiSE4
2006 Creating Objects in the Flexible Authorization Framework
Nicola Zannone, Sushil Jajodia, Duminda Wijesekera
DBSec1
2006 Detecting Conflicts of Interest
abstract
System vulnerabilities are often caused by the presence of conflicts within the organization where the system-to-be would eventually operate. In particular, conflicts of interest are very harmful since actors can exploit their positions/roles relative to the system for gaining personal advantage. Capturing and resolving such conflicts is a necessary condition for developing secure information systems. In this paper, we show how conflicts of interest can be formally detected during requirements analysis. This allows system designers to investigate the causes for which conflicts may occur in an organization. Thereby, they can better understand the organizational structure and so provide appropriate countermeasures to resolve or at least mitigate them
Paolo Giorgini, Fabio Massacci, John Mylopoulos, Nicola Zannone
RE4
2006 Hierarchical hippocratic databases with minimal disclosure for virtual organizations
Fabio Massacci, John Mylopoulos, Nicola Zannone
VLDB J.3
2005 Minimal Disclosure in Hierarchical Hippocratic Databases with Delegation
Fabio Massacci, John Mylopoulos, Nicola Zannone
ESORICS3
2005 Modeling Security Requirements Through Ownership, Permission and Delegation
abstract
Security requirements engineering is emerging as a branch of software engineering, spurred by the realization that security must be dealt with early on during the requirements phase. Methodologies in this field are challenging, as they must take into account subtle notions such as trust (or lack thereof), delegation, and permission; they must also model entire organizations and not only systems-to-be. In our previous work we introduced Secure Tropos, a formal framework for modeling and analyzing security requirements. Secure Tropos is founded on three main notions: ownership, trust, and delegation. In this paper, we refine Secure Tropos introducing the notions of at-least delegation and trust of execution; also, at-most delegation and trust of permission. We also propose monitoring as a security design pattern intended to overcome the problem of lack of trust between actors. The paper presents a semantic for these notions, and describes an implemented formal reasoning tool based on Datalog.
Paolo Giorgini, Fabio Massacci, John Mylopoulos, Nicola Zannone
RE4
2005 ST-Tool: A CASE Tool for Security Requirements Engineering
abstract
Security requirements engineering is emerging as a branch of software engineering, spurred by the realization that security must be dealt with early on during the requirements phase. We propose ST-tool, a CASE tool developed for modeling and analyzing functional and security requirements.
Paolo Giorgini, Fabio Massacci, John Mylopoulos, Nicola Zannone
RE4