EDBT 2026 Demo / reviewers in the wild / expert
Angelo Furfaro
dblp:94/6215
· DBLP profile ↗
30ranked-venue papers
9as first author
4since 2021 · last 2026
0000-0003-2537-8918ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 11 · 1 first-authorSystems, architecture and hardware · 6 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 5 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-authorSecurity and privacy · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorComputer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CyberRAG: An agentic RAG cyber attack classification and reporting toolabstractIntrusion Detection and Prevention Systems (IDS/IPS) in large enterprises can generate hundreds of thousands of alerts per hour, overwhelming analysts with logs requiring rapidly evolving expertise. Conventional machine-learning detectors reduce alert volume but still yield many false positives, while standard Retrieval-Augmented Generation (RAG) pipelines often retrieve irrelevant context and fail to justify predictions. We present CyberRAG, a modular agent-based RAG framework that delivers real-time classification, explanation, and structured reporting for cyber-attacks. A central LLM agent orchestrates: (i) fine-tuned classifiers specialized by attack family; (ii) tool adapters for enrichment and alerting; and (iii) an iterative retrieval-and-reason loop that queries a domain-specific knowledge base until evidence is relevant and self-consistent. Unlike traditional RAG, CyberRAG adopts an agentic design that enables dynamic control flow and adaptive reasoning. This architecture autonomously refines threat labels and natural-language justifications, reducing false positives and enhancing interpretability. It is also extensible: new attack types can be supported by adding classifiers without retraining the core agent. CyberRAG was evaluated on SQL Injection, XSS, and SSTI, achieving over 94% accuracy per class and a final classification accuracy of 94.92% through semantic orchestration. Generated explanations reached 0.94 in BERTScore and 4.9/5 in GPT-4-based expert evaluation, with robustness preserved against adversarial and unseen payloads. These results show that agentic, specialist-oriented RAG can combine high detection accuracy with trustworthy, SOC-ready prose, offering a flexible path toward partially automated cyber-defense workflows. Francesco Blefari, Cristian Cosentino, Francesco Aurelio Pironti, Angelo Furfaro, Fabrizio Marozzo |
Future Gener. Comput. Syst. | 4 |
| 2024 | Toward a Log-based Anomaly Detection System for Cyber Range PlatformsabstractNowadays, the Information Technology landscape is permeated by a multitude of vulnerabilities and threats. The constantly rising number of heterogeneous devices makes difficult or even impossible a complete mapping of all possible threats to which they are exposed. Antivirus and Anti-malware tools have been developed to quickly detect anomalous software or behaviors. However, these solutions often rely on a knowledge base stored in such a kind of database. They are not effective against unknown attacks, also known as zero-day attacks. By relying on (network/system) log analysis it is possible to detect attacker activities. The log analysis plays a crucial role against cyber threats providing an effective tool in order to detect them rapidly and build advanced monitoring systems. However, log consultation can often be a challenging and costly task. Over time, useful tools and utilities have been developed to simplify the task for analysts. This paper presents a system capable to detect attackers’ activities in a Cyber Range platform. The system also features the visualization of attackers’ activity traces represented as attack graphs. Francesco Blefari, Francesco Aurelio Pironti, Angelo Furfaro |
ARES | 3 |
| 2024 | Combining Anti-typosquatting Techniques
Francesco Blefari, Angelo Furfaro, Giovambattista Ianni, Alessandro Viscomi |
ICWE | 2 |
| 2023 | HoneyICS: A High-interaction Physics-aware Honeynet for Industrial Control SystemsabstractIndustrial control systems (ICSs) are vulnerable to cyber-physical attacks, i.e., security breaches in cyberspace that adversely affect the underlying physical processes. In this context, honeypots are effective countermeasures both to defend against such attacks and discover new attack strategies. In recent years, honeypots for ICSs have made significant progress in faithfully emulating OT networks, including physical process interactions. We propose HoneyICS, a high-interaction, physics-aware, scalable, and extensible honeynet for ICSs, equipped with an advanced monitoring system. We deployed our honeynet on the Internet and conducted experiments to evaluate the effectiveness of HoneyICS. Marco Lucchese, Francesco Lupia, Massimo Merro, Federica Paci, Nicola Zannone, Angelo Furfaro |
ARES | 6 |
| 2018 | Exploiting Adaptive Ladder Queue into Repast Simulation platformabstractEfficiently scheduling the pending event set of a discrete event simulator is a challenging problem. A critical point consists in identifying the most suitable data structure to ensure good performances of the simulation engine. Adaptive Ladder Queue (ALQ) proved to outperform other data structures available in literature, claiming O(1) amortized access time both in theory and in practice. Its value comes out even when used in other contexts. Agent-based modelling and simulation tools are largely catching on and provide a considerable opportunity to investigate ALQ performance. This paper provides an illustration of the potential of the above introduced data structure, in the context of Repast Simphony, a Java-based modelling system. Angelo Furfaro, Ludovica Sacco |
DS-RT | 1 |
| 2018 | Using CalcuList To MapReduce JsonsabstractCalcuList (Calculator with List manipulation), is an educational language for teaching functional programming extended with some imperative and side-effect features, which are enabled under explicit request by the programmer. In addition to strings and lists, the language natively supports json objects and may be effectively used to implement generic MapReduce recursive procedures to manipulate json lists. MapReduce is a popular model in distributed computing that underpins many NoSQL systems and a json list can be thought of as a dataset of a document NoSQL datastore. It turns out that CalcuList can be used as a tool for teaching advanced query algorithms for document datastores such as MongoDB and CouchDB. Domenico Saccà, Angelo Furfaro |
IDEAS | 2 |
| 2018 | Adaptive Ladder Queue: Achieving O(1) Amortized Access Time in PracticeabstractThe data structure that handles the pending event set of a discrete event simulator is a critical component in that its performances have a direct impact on those of the overall simulation engine. Many data structures have been proposed in the literature. Among them, the Ladder Queue (LadderQ) claims $O(1)$ amortized access time. However, empirical results show that the practical achievement of such performances is highly dependent on the distribution of event timestamps and that in many cases are similar or even worse than those of heap-based priority queues. This paper proposes an adaptive extension of the LadderQ which overcomes most of its weaknesses and allows to achieve $O(1)$ amortized access time in practice. Angelo Furfaro, Ludovica Sacco |
SIGSIM-PADS | 1 |
| 2018 | Cybersecurity compliance analysis as a service: Requirements specification and application scenariosabstractSummary Cybersecurity compliance analysis is the process of assessing whether the behavior of an IT system or application conforms to the cybersecurity rules and regulations in force. This assessment can be offered as a service by exploiting available cloud technologies, and, indeed, it is one of the services classified by the Cloud Security Alliance (CSA) as part of the security information and event management (SIEM) category of the SecaaS (security as a service) domain. The definition and implementation of this typology of cloud services are challenging activities due to the complexity of both the reference business domain and the compliance analysis services to be provided themselves. The paper exploits a recently proposed requirements methodology, called GOReM (goal‐oriented requirements methodology), to support the conceptualization and subsequent implementation of cybersecurity compliance analysis services. In particular, two different application scenarios regarding compliance analysis of an existing or under development IT system/application are presented and discussed. In both the scenarios, GOReM allows to grasp and understand the many and complex issues to address for providing secure cloud services to worldwide customers, also due to the numerous, different and ever changing legal aspects, which have to be taken into account by service providers. Angelo Furfaro, Teresa Gallo, Alfredo Garro, Domenico Saccà, Andrea Tundis |
Concurr. Comput. Pract. Exp. | 1 |
| 2018 | A Cloud-based platform for the emulation of complex cybersecurity scenarios
Angelo Furfaro, Antonio Piccolo, Andrea Parise, Luciano Argento, Domenico Saccà |
Future Gener. Comput. Syst. | 1 |
| 2018 | Exploiting Content Spatial Distribution to Improve Detection of IntrusionsabstractWe present PCkAD, a novel semisupervised anomaly-based IDS (Intrusion Detection System) technique, detecting application-level content-based attacks. Its peculiarity is to learn legitimate payloads by splitting packets into chunks and determining the within-packet distribution of n-grams. This strategy is resistant to evasion techniques as blending. We prove that finding the right legitimate content is NP-hard in the presence of chunks. Moreover, it improves the false-positive rate for a given detection rate with respect to the case where the spatial information is not considered. Comparison with well-known IDSs using n-grams highlights that PCkAD achieves state-of-the-art performances. Fabrizio Angiulli, Luciano Argento, Angelo Furfaro |
ACM Trans. Internet Techn. | 3 |
| 2017 | 2D Motif Basis Applied to the Classification of Digital ImagesabstractThe classification of raw data often involves the problem of selecting the appropriate set of features to represent the input data. Different types of features can be extracted from the input dataset, but only some of them are actually relevant for the classification process. Since relevant features are often unknown in real-world problems, many candidate features are usually introduced. This degrades both the speed and the predictive accuracy of the classifier due to the presence of redundancy in the set of candidate features. Recently, a special class of bidimensional motifs, i.e. 2D motif basis has been introduced in the literature. 2D motif basis showed to be powerful in capturing the relevant information of digital images, also achieving good performances for image compression. Here, we investigate the effectiveness of 2D motif basis, when they are used as features for image classification. We embed such features in a bag-of-words model, and then we apply K-Nearest Neighbour for the classification step. Results obtained on both benchmark image datasets and video frames datasets show that, despite the pixel-level nature of the considered features, the achieved accuracy is high and comparable with that of other techniques proposed in the literature. Angelo Furfaro, Maria Carmela Groccia, Simona E. Rombo |
Comput. J. | 1 |
| 2016 | ResDevOps: A Software Engineering Framework for Achieving Long-Lasting Complex SystemsabstractThe development of high quality complex software systems and quick time-to-market with full customer satisfaction often appear as two competing forces. Many industry efforts have been directed towards agile methodologies completed with the DevOps approach, whereas traditional requirements engineering with much documentation, is considered surpassed. The aim is to obtain a longer life software because it suddenly responds to the customers changing requirements from which it receives continuous input. This might create a serious cost implication and a real risk to lose system requirements control. In this paper, we propose a framework able to govern the complexity of the system requirements and to allow the embedding, occasionally, of technological innovations into the overall system. ResDevOps joins the value of the agile world with DevOps, with the additional value deriving from an unceasing parallel innovation management process, which we call ResDevs. ResDevOps includes a continuous research and innovation process, which provides an asynchronous, additional input to the agile process inside a chain of concurrent engineering collaboration. This is a suitable trade-off to maintain modern IT Systems live for a longer time, with many consequent advantages for both total investment and system quality. The practical use of the ResDevOps approach is shown by means of a case study. Angelo Furfaro, Teresa Gallo, Alfredo Garro, Domenico Saccà, Andrea Tundis |
RE | 1 |
| 2015 | A multi-protocol framework for the development of collaborative virtual environmentsabstractCollaborative virtual environments (CVEs) are used for collaboration and interaction of possibly many participants that may be spread over large distances. Both commercial and freely available CVEs exist today. Currently, CVEs are used already in a variety of different fields: gaming, business, education, social communication, and cooperative development In this paper, a general framework is proposed for the development of a cooperative environment which is able to exploit a multi protocol network infrastructure. The framework offers support to concerns such as communication security and inter-protocol interoperability and let software engineers to focus on the specific business of the CVE under development. To show the framework effectiveness we consider, as a case of study, the design of a reusable software layer for the development of distributed card games built on top of it. This layer is, in turn, used for the implementation of a specific card game. Luciano Argento, Angelo Furfaro |
CSCWD | 2 |
| 2015 | Exploiting N-Gram Location for Intrusion DetectionabstractSignature-based and protocol-based intrusion detection systems (IDS) are employed as means to reveal content-based network attacks. Such systems have proven to be effective in identifying known intrusion attempts and exploits but they fail to recognize new types of attacks or carefully crafted variants of well known ones. This paper presents the design and the development of an anomaly-based IDS technique which is able to detect content-based attacks carried out over application level protocols, like HTTP and FTP. In order to identify anomalous packets, the payload is split up in chunks of equal length and the n-gram technique is used to learn which byte sequences usually appear in each chunk. The devised technique builds a different model for each pair and uses them to classify the incoming traffic. Models are build by means of a semi-supervised approach. Experimental results witness that the technique achieves an excellent accuracy with a very low false positive rate. Fabrizio Angiulli, Luciano Argento, Angelo Furfaro |
ICTAI | 3 |
| 2015 | An analytical processing approach to supporting cyber security compliance assessmentabstractCompliance analysis is an important step for the security management process of systems. It aims at both increasing service quality and reducing service vulnerabilities by exploiting security mechanisms able to improve the fulfillment of requirements whose failure may cause direct and indirect costs, related to the existence of missed normative provisions, risk of loss of certifications, and increased probability and impact of security incidents. Due to the increasing in system complexity there are hundreds of requirements that must be observed simultaneously and satisfied. As a consequence, the need for innovative approaches centered on effective solutions able to support the evaluation and the validation of requirements and constraints over the time is today greater than ever. In this context, the paper proposes a method for supporting the compliance assessment of services, in respect of norms and regulations, exploitable both in design phase or during the operation of existing services supported by (semi-)automatic tools. The effectiveness of the method is then tested through a case study taken from the experience of the Computer Emergency Response Team (CERT) of Poste Italiane, concerning the compliance assessment of an Electronic Payment Service by credit card. Francesco Buccafurri, Lidia Fotia, Angelo Furfaro, Alfredo Garro, Matteo Giacalone, Andrea Tundis |
SIN | 3 |
| 2013 | Agent Methodological Layers In Repast SimphonyabstractRepast Simphony (RS) is a popular toolbox for agentbased modeling and simulation (ABMS) of complex systems. It can be used from within the Eclipse IDE with Java being the main implementation language. Moreover, visual modeling is supported by agent flowcharts. Powerful features of RS include contexts and projections which allow the modeler to build e.g. situated multi-agent systems (MAS) which can easily be configured and visualized in the RS runtime system. RS lacks of a reference agent methodology. Rather the modeler is free to define and follow her/his own methodology with RS: procedurally, declaratively or visual-based. This openness was exploited in this work for supporting different notions of agents, thus addressing the modeling needs of various application domains. In particular this paper proposes an embed in RS of an actor model which provides a lightweight notion of agents. The actor model is then used as a kernel for supporting more abstract but rigorous modeling languages like Parallel DEVS (P−DEVS) and time-extended Petri nets. A P−DEVS modeling example is reported to demonstrate the usefulness of supporting multiple agent methodological layers in RS. Franco Cicirelli, Angelo Furfaro, Libero Nigro, Francesco Pupo |
ECMS | 2 |
| 2013 | Modelling Java Concurrency: An Approach and a Uppaal Library
Franco Cicirelli, Angelo Furfaro, Libero Nigro, Francesco Pupo |
FedCSIS | 2 |
| 2013 | Image Classification Based on 2D Feature Motifs
Angelo Furfaro, Maria Carmela Groccia, Simona E. Rombo |
FQAS | 1 |
| 2012 | Development of a Schedulability Analysis Framework Based on pTPN and UPPAAL with StopwatchesabstractThis paper proposes an original schedulability framework which is based on preemptive Time Petri Nets (pTPNs) and UPPAAL with stopwatches (UPPAALSW). The realization enables a real-time tasking set, along with precedence constraints in the form of data control, message passing etc., to be uniformly formalized using pTPNs and then analyzed through model checking using UPPAALSW in the presence of a reusable library of template processes modelling transitions of the source pTPNs specification and the scheduler algorithm which can be based on fixed priority or earliest deadline first. The paper first introduces and motivates the proposed approach by relating it to similar work described in literature, then summarizes the pTPNs formalism through a modelling example. After that the prototyped library in UPPAALSW is presented and put to work for model checking the chosen real-time tasking set. Analysis of models which depend e.g. on non deterministic execution times and sporadic arrival times of tasks, is conditioned by the use of an over approximation in the generation of the model state graph. Franco Cicirelli, Angelo Furfaro, Libero Nigro, Francesco Pupo |
DS-RT | 2 |
| 2012 | Agents Over The Grid: An Experience Using The Globus Toolkit 4abstractThis paper describes an experience of porting the THEATRE agent architecture on top of the grid. The agent architecture consists of light-weight actors and computational theatres which have been proven to be well suited for modeling and simulation of complex systems. THEATRE nodes act as agencies that provide common services of message scheduling and dispatching to mobile actors. THEATRE is currently implemented in Java and can work with different transport layers and middleware. In the last years it was successfully interfaced to HLA/RTI, Terracotta, Java Sockets and Java RMI. The work described in this paper aims at experimenting with THEATRE over the grid, using in particular the Globus toolkit. The goal is to open THEATRE to the exploitation of virtual organizations of computing resources with secure communications, and to favor simulation interoperability through grid services. The paper summarizes THEATRE, describes a design and prototype implementation of THEATRE on top of the Globus Toolkit 4 (GT4), and demonstrates its practical use by means of a modeling example. Franco Cicirelli, Angelo Furfaro, Libero Nigro, Francesco Pupo |
ECMS | 2 |
| 2011 | Dynamic Sociality Minority GameabstractThe minority game (MG) is a simple yet effective binary-decision model which is well suited to study the collec-tive emerging behaviour in a population of agents with bounded and inductive rationality when they have to compete, through adaptation, for scarce resources. The original formulation of the MG was inspired by the W.B. Arthur’s El Farol Bar problem in which a fixed num-ber of people have to independently decide each week whether to go to a bar having a limited capacity. A de-cision is only affected by information on the number of visitors who attended the bar in the past weeks. In its basic version, the MG does not contemplate communi-cation among players and it supposes that information about the past game outcomes is publicly available. This paper proposes the Dynamic Sociality Minority Game (DSMG), an original variant of the classic MG where (i) information about the outcome of the previously played game step is assumed to be known only by the agents that really attended the bar the previous week and (ii) a dynamically established acquaintance relationship is in-troduced to propagate such information among non at-tendant players. Particular game settings are identified which make DSMG able to exhibits a better coordina-tion level among players with respect to standard MG. Behavioral properties of the DSMG are thoroughly an-alyzed through an agent-based simulation of a simple road-traffic model. Franco Cicirelli, Angelo Furfaro, Libero Nigro, Francesco Pupo |
ECMS | 2 |
| 2010 | Parallel Simulation of Multi-agent Systems Using TerracottaabstractThis paper describes a novel approach to parallel simulation of complex multi-agent systems which is based on actors and the Java middleware Terracotta. The approach aims to an exploitation of the computing power of modern multicore machines. Terracotta was chosen because it transparently allows to cluster the JVM. The paper discusses design and implementation aspects of the approach, and demonstrates the achievable execution performance through the parallel simulation of a scalable multi-agent system based on the predator/prey model. Franco Cicirelli, Angelo Furfaro, Libero Nigro |
DS-RT | 2 |
| 2010 | A service-based architecture for dynamically reconfigurable workflows
Franco Cicirelli, Angelo Furfaro, Libero Nigro |
J. Syst. Softw. | 2 |
| 2009 | Distributed Simulation of RePast Models over HLA/ActorsabstractThis paper reports about a research project-HLA ACTOR REPAST- aimed to distributing RePast models thus potentially corresponding to the computational demands of large and reconfigurable multi-agent systems (MASs). Novel in HLA ACTOR REPAST is an exploitation of a lean actor infrastructure implemented in Java. Actors bring to RePast agents such features as migration, location-transparent naming,efficient communications, and a control-centric framework.Actors can be orchestrated by an in-the-large custom control structure which can ensure the necessary message causality constraints. Distribution and time management concerns depend on the IEEE standard HLA middleware. The paper first discusses details of the software engineering process underlying HLA ACTOR REPAST. The mapping techniques, based on Java text annotations and aspect oriented programming, minimize¿code intrusions¿ in the original model. Then the paper describes some experiments and performance results of applying HLA ACTOR REPAST to a distributed version of a RePast Tileworld model. Franco Cicirelli, Angelo Furfaro, Libero Nigro |
DS-RT | 2 |
| 2009 | Distributing RePast Simulations Using ActorsabstractRePast is a well-known agent-based toolkit for modelling and simulation of complex systems. The toolkit is normally used on a single workstation, where modelling, execution and visualization aspects are dealt with. This paper describes an approach aimed to distributing RePast models, with minimal changes, over a networked context so as to address very large and reconfigurable models whose computational needs (in space and time) can be difficult to satisfy on a single machine. Novel in the approach is an exploitation of a lean actor infrastructure implemented in Java. Actors bring to RePast agents migration, location-transparent naming, efficient communications, and a control-centric framework. Actors can be orchestrated by an in-thelarge custom control structure which can ensure the necessary message precedence constraints. Preliminary experience is being carried out using HLA/RTI as middleware. However, the realization can also work with other standard transport layers such as Java Socket and Java RMI. The paper introduces the design rationale behind mapping RePast on to actors and discusses a distributed example. Franco Cicirelli, Angelo Furfaro, Libero Nigro |
ECMS | 2 |
| 2009 | Statechart-Based Actors For Modelling And Distributed Simulation Of Complex Multi-Agent SystemsabstractThis paper discusses the use of Theatre, a multi-agent simulation architecture, for the distributed simulation of discrete event systems (DESs) whose entities express complex behaviours. Complexity is dealt with by exploiting statechart-based actors which constitute the basic building blocks of a model. Actors are lightweight reactive autonomous agents that communicate to one another by asynchronous message passing. The threadless character of actors saves memory space and fosters efficient execution. The behaviour of actors is specified through “distilled statecharts” that enable hierarchical and modular specifications. Distributed simulation is accomplished by partitioning the system model among a set of logical processes (theatres). Timing management and intertheatre communications rest on High Level Architecture (HLA) services. The paper highlights the current implementation status and demonstrates the practical application of the approach through a manufacturing system model. Franco Cicirelli, Angelo Furfaro, Libero Nigro |
ECMS | 2 |
| 2007 | Exploiting agents for modelling and simulation of coverage control protocols in large sensor networks
Franco Cicirelli, Angelo Furfaro, Libero Nigro |
J. Syst. Softw. | 2 |
| 2007 | Distributed simulation of modular time Petri nets: An approach and a case study exploiting temporal uncertainty
Franco Cicirelli, Angelo Furfaro, Libero Nigro |
Real Time Syst. | 2 |
| 2006 | Modular Design of Real-Time Systems Using Hierarchical Communicating Real-time State Machines
Angelo Furfaro, Libero Nigro, Francesco Pupo |
Real Time Syst. | 1 |
| 2005 | Model checking hierarchical communicating real-time state machinesabstractHierarchical communicating real-time state machines (H-CRSM) is a formal modelling language for the modular development of distributed real-time systems. The formalism is characterized by the use of state transitions with guarded commands and timing constraints, the adoption of a few distilled statecharts constructs, and the modular specification of timing constraints along a state hierarchy. This paper proposes a translation of H-CRSM into UPPAAL which enables model checking. Translation rests on unfolding a hierarchical model on a flat representation Angelo Furfaro, Libero Nigro |
ETFA | 1 |