EDBT 2026 Demo / reviewers in the wild / expert
Luca Compagna
dblp:c/LucaCompagna
· DBLP profile ↗
33ranked-venue papers
5as first author
7since 2021 · last 2025
0009-0003-1072-4352ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 11 · 3 first-authorArtificial intelligence and machine learning · 5 · 1 first-authorTheory of computation · 5Applied, interdisciplinary, general and emerging computing · 2 · 2 first-authorComputer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | One Detector Fits All: Robust and Adaptive Detection of Malicious Packages from PyPI to EnterprisesabstractThe rise of supply chain attacks via malicious Python packages calls for robust and adaptable detection solutions. However, current approaches overlook two critical challenges: (i) robustness to adversarial source code transformations, and (ii) the lack of adaptability to different actors in the software supply chain with different false positive rate (FPR) requirements, from repository maintainers (very low FPR) to enterprise security teams (higher FPR tolerance). To address these challenges, in this work we introduce a new robust detector that can be seamlessly integrated into both public repositories like PyPI and enterprise ecosystems. To thoroughly evaluate the robustness of our detector, we propose a novel methodology to generate adversarial packages by leveraging a new set of fine-grained code transformations based on code obfuscation techniques. By combining these adversarial packages with adversarial training (AT), we enhance the robustness of our detector by 2.5×. We comprehensively evaluate the effectiveness of AT by testing our detector against a large dataset of 122,398 packages collected daily from PyPI over 80 days, showing that AT needs to be applied carefully: on the one hand, it makes the detector more robust to obfuscations and allows finding 10% more obfuscated packages, but on the other hand it introduces a negative effect by slightly decreasing the performance on non-obfuscated packages. To demonstrate its adaptability in production, we conduct two vetting case studies by tuning the detector to different FPR thresholds: (i) one for PyPI maintainers with a low FPR (0.1%) and (ii) one for enterprise security teams with a higher FPR (10%). In the first case study, we evaluate our final detector on 91,949 packages collected over 37 days, achieving an average daily detection rate of 2.48 malicious packages with only 2.18 false positives per day. In the second one, we analyze 1,596 packages adopted by a multinational software company, achieving only 1.24 false positives on average per day. These results show that our detector can be seamlessly integrated into both public repositories like PyPI and enterprise ecosystems, ensuring a very low time budget of a few minutes to review the false positives. Overall, our detector uncovered a total of 346 malicious packages, now reported to the community. Biagio Montaruli, Luca Compagna, Serena Elisa Ponta, Davide Balzarotti |
ACSAC | 2 |
| 2025 | ModSec-AdvLearn: Countering Adversarial SQL Injections With Robust Machine LearningabstractMany Web Application Firewalls (WAFs) leverage the OWASP Core Rule Set (CRS) to block incoming malicious requests. The CRS consists of different sets of rules designed by domain experts to detect well-known web attack patterns. Both the set of rules and the weights used to combine them are manually defined, yielding four different default configurations of the CRS. In this work, we focus on the detection of SQL injection (SQLi) attacks, and show that the manual configurations of the CRS typically yield a suboptimal trade-off between detection and false alarm rates. Furthermore, we show that these configurations are not robust to adversarial SQLi attacks, i.e., carefully-crafted attacks that iteratively refine the malicious SQLi payload by querying the target WAF to bypass detection. To overcome these limitations, we propose (i) using machine learning to automate the selection of the set of rules to be combined along with their weights, i.e., customizing the CRS configuration based on the monitored web services; and (ii) leveraging adversarial training to significantly improve its robustness to adversarial SQLi manipulations. Our experiments, conducted using the well-known open-source ModSecurity WAF equipped with the CRS rules, show that our approach, named ModSec-AdvLearn, can (i) increase the detection rate up to 30%, while retaining negligible false alarm rates and discarding up to 50% of the CRS rules; and (ii) improve robustness against adversarial SQLi attacks up to 85%, marking a significant stride toward designing more effective and robustWAFs.We release our open-source code at https://github.com/pralab/modsec-advlearn. Giuseppe Floris, Christian Scano, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras 0001, Davide Balzarotti, Battista Biggio |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | CSRFing the SSO Waves: Security Testing of SSO-Based Account Linking ProcessabstractThe Single Sign-On based account linking process (SSOLinking in short) allows users to link their accounts at Service Provider (SP) websites to their Identity Providers (IdP) accounts. We focus on a serious (and overlooked) attack, namely an Account Hijack targeting the SSOLinking and relying on two CSRF vulnerabilities, one affecting the IdP and the other the SP. The former is an Authentication CSRF (also known as Login CSRF) and the latter is a CSRF on the button triggering the SSOLinking. We propose a security testing approach to help testers automatically detect such attacks. We implemented our testing technique as an extension (namely SSOLinking Checker) to the open-source penetration testing tool Micro-Id-Gym. To demonstrate the effectiveness of our approach and the pervasiveness of the SSOLinking Account Hijack, we conducted an experimental analysis against a selection of popular SPs that offer the SSOLinking with major IdPs. The results of our experiments are alarming: out of the 648 web sites we considered, 48 qualified for conducting our experiments and 21 of these suffered from SSOLinking vulnerability (i.e. 43.7%). Our findings (we responsibly disclosed to the affected vendors) include severe vulnerabilities among the web sites of Goodreads, Naver, Workable, etc. Andrea Bisegna, Matteo Bitussi, Roberto Carbone, Luca Compagna, Silvio Ranise, Avinash Sudhodanan |
EuroS&P | 4 |
| 2024 | FP-tracer: Fine-grained Browser Fingerprinting Detection via Taint-tracking and Entropy-based ThresholdsabstractBrowser fingerprinting is an effective technique to track web users by building a fingerprint from their browser attributes. It is also stealthy because the tracker uses legitimate JavaScript API calls offered by the browser engine, which can be obfuscated before they are sent to a (third-party) server. Current browser fingerprinting methodologies employ coarse-grained collection and classification techniques, such as binary classification of fingerprinters based on the number of non-obfuscated exfiltrated attributes. As a result, they produce inconsistent findings. Meanwhile, the privacy of millions of web users is at risk daily. We address this gap by presenting FP-tracer, a novel methodology to detect and classify browser fingerprinters based on dynamic taint tracking and joint entropy classification. Our methodology enables detecting first- and third-party fingerprinters even when they use obfuscation by tainting attributes, propagating them, and logging when they are leaked (via 62 sources and 25 sinks). Moreover, it discriminates the invasiveness of fingerprinting activities, even from the same service, by measuring the joint entropy of the collected attributes and clustering them. We implement FP-tracer by extending Foxhound, a privacy-oriented Firefox fork with numeric type tainting, more taint tracking sources and sinks, support for multiple sources, and better logging capabilities. We embed our implementation in our automated crawling infrastructure, which is capable of testing websites in parallel using programmable and reproducible logic. We will open-source our implementation. We evaluate FP-tracer by performing a large-scale crawl over the Tranco Top 100K, and detect, amongst others, audio, canvas, and storage fingerprinting on the web. Among others, we find high fingerprinting activities in 8% of domains, with more moderate activity reaching 75%. Notably, fingerprinting is almost five times more likely to be performed by third-party scripts for high activity levels. In addition, we measure that the most severe category of fingerprinting obfuscates 46% of transmitted attributes, and 38% of fingerprinters involve two or more domains. Finally, we find that existing consent banners do not provide an effective defense against browser fingerprinting Soumaya Boussaha, Lukas Hock, Miguel Bermejo, Rubén Cuevas Rumín, Ángel Cuevas, David Klein 0001, Martin Johns, Luca Compagna, Daniele Antonioli, Thomas Barber |
Proc. Priv. Enhancing Technol. | 8 |
| 2023 | WHIP: Improving Static Vulnerability Detection in Web Application by Forcing tools to Collaborate
Feras Al Kassar, Luca Compagna, Davide Balzarotti |
USENIX Security Symposium | 2 |
| 2022 | The Convergence of Source Code and Binary Vulnerability Discovery - A Case StudyabstractDecompilers are tools designed to recover a high-level language representation (typically in C code) from program binaries. Over the past five years, decompilers have improved enormously, not only in terms of the readability of the produced pseudocode, but also in terms of similarity of the recovered representation to the original source code. Albeit decompilers are routinely used by reverse engineers in different disciplines (e.g., to support vulnerability discovery or malware analysis), they are not yet adopted to produce input for source-code static analysis tools. In particular, source code vulnerability discovery and binary vulnerability discovery remain today two very different areas of research, despite the fact that decompilers could potentially bridge this gap and enable source-code analysis on binary files. Alessandro Mantovani, Luca Compagna, Yan Shoshitaishvili, Davide Balzarotti |
AsiaCCS | 2 |
| 2022 | Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications
Feras Al Kassar, Giulia Clerici, Luca Compagna, Davide Balzarotti, Fabian Yamaguchi |
NDSS | 3 |
| 2020 | Bulwark: Holistic and Verified Security Monitoring of Web Protocols
Lorenzo Veronese, Stefano Calzavara, Luca Compagna |
ESORICS (1) | 3 |
| 2017 | Aegis: Automatic Enforcement of Security Policies in Workflow-driven Web ApplicationsabstractOrganizations often expose business processes and services as web applications. Improper enforcement of security policies in these applications leads to business logic vulnerabilities that are hard to find and may have dramatic security implications. Aegis is a tool to automatically synthesize run-time monitors to enforce control-flow and data-flow integrity, as well as authorization policies and constraints in web applications. The enforcement of these properties can mitigate attacks, e.g., authorization bypass and workflow violations, while allowing regulatory compliance in the form of, e.g., Separation of Duty. Aegis is capable of guaranteeing business continuity while enforcing the security policies. We evaluate Aegis on a set of real-world applications, assessing the enforcement of policies, mitigation of vulnerabilities, and performance overhead. Luca Compagna, Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
CODASPY | 1 |
| 2017 | Large-Scale Analysis & Detection of Authentication Cross-Site Request ForgeriesabstractCross-Site Request Forgery (CSRF) attacks are one of the critical threats to web applications. In this paper, we focus on CSRF attacks targeting web sites' authentication and identity management functionalities. We will refer to them collectively as Authentication CSRF (Auth-CSRF in short). We started by collecting several Auth-CSRF attacks reported in the literature, then analyzed their underlying strategies and identified 7 security testing strategies that can help a manual tester uncover vulnerabilities enabling Auth-CSRF. In order to check the effectiveness of our testing strategies and to estimate the incidence of Auth-CSRF, we conducted an experimental analysis considering 300 web sites belonging to 3 different rank ranges of the Alexa global top 1500. The results of our experiments are alarming: out of the 300 web sites we considered, 133 qualified for conducting our experiments and 90 of these suffered from at least one vulnerability enabling Auth-CSRF (i.e. 68%). We further generalized our testing strategies, enhanced them with the knowledge we acquired during our experiments and implemented them as an extension (namely CSRF-checker) to the open-source penetration testing tool OWASP ZAP. With the help of CSRFchecker, we tested 132 additional web sites (again from the Alexa global top 1500) and identified 95 vulnerable ones (i.e. 72%). Our findings include serious vulnerabilities among the web sites of Microsoft, Google, eBay etc. Finally, we responsibly disclosed our findings to the affected vendors. Avinash Sudhodanan, Roberto Carbone, Luca Compagna, Nicolas Dolgin, Alessandro Armando, Umberto Morelli |
EuroS&P | 3 |
| 2017 | Automatically finding execution scenarios to deploy security-sensitive workflowsabstractWe introduce a new class of analysis problems, called Scenario Finding Problems (SFPs), for security-sensitive business processes that – besides execution constraints on tasks – define access control policies (constraining which users can execute which tasks) and authorization constraints (such as Separation of Duty). The solutions to SFPs are concrete execution scenarios that assist customers in the reuse and deployment of security-sensitive workflows. We study the relationship of SFPs to well-known properties of security-sensitive processes such as Workflow Satisfiability and Resiliency together with their complexity. Finally, we present a symbolic approach to solving SFPs and describe our experience with a prototype implementation on real-world business process models taken from an on-line library. Daniel Ricardo dos Santos, Silvio Ranise, Luca Compagna, Serena Elisa Ponta |
J. Comput. Secur. | 3 |
| 2016 | Attack Patterns for Black-Box Security Testing of Multi-Party Web Applications
Avinash Sudhodanan, Alessandro Armando, Roberto Carbone, Luca Compagna |
NDSS | 4 |
| 2016 | Cerberus: Automated Synthesis of Enforcement Mechanisms for Security-Sensitive Business Processes
Luca Compagna, Daniel Ricardo dos Santos, Serena Elisa Ponta, Silvio Ranise |
TACAS | 1 |
| 2016 | SATMC: a SAT-based model checker for security protocols, business processes, and security APIs
Alessandro Armando, Roberto Carbone, Luca Compagna |
Int. J. Softw. Tools Technol. Transf. | 3 |
| 2015 | Assisting the Deployment of Security-Sensitive Workflows by Finding Execution Scenarios
Daniel Ricardo dos Santos, Silvio Ranise, Luca Compagna, Serena Elisa Ponta |
DBSec | 3 |
| 2015 | Security Threat Identification and TestingabstractBusiness applications are more and more collaborative (cross-domains, cross-devices, service composition). Security shall focus on the overall application scenario including the interplay between its entities/devices/services, not only on the isolated systems within it. In this paper we propose the Security Threat Identification And TEsting (STIATE) toolkit to support development teams toward security assessment of their under-development applications focusing on subtle security logic flaws that may go undetected by using current industrial technology. At design-time, STIATE supports the development teams toward threat modeling and analysis by identifying automatically potential threats (via model checking and mutation techniques) on top of sequence diagrams enriched with security annotations (including WHAT-IF conditions). At run-time, STIATE supports the development teams toward testing by exploiting the identified threats to automatically generate and execute test cases on the up and running application. We demonstrate the usage of the STIATE toolkit on an application scenario employing the SAML Single Sign-On multi-party protocol, a well-known industrial security standard largely studied in previous literature. Roberto Carbone, Luca Compagna, Annibale Panichella, Serena Elisa Ponta |
ICST | 2 |
| 2014 | SATMC: A SAT-Based Model Checker for Security-Critical Systems
Alessandro Armando, Roberto Carbone, Luca Compagna |
TACAS | 3 |
| 2013 | Business Process Compliance via Security Validation as a ServiceabstractModern enterprise systems are often process-based, i.e., they allow for the direct execution of business processes that are specified in a high-level language such as BPMN. In this paper, we present a service, called Security Validation as a Service (SVaaS) for validating the compliance of the business processes during design-time. Basically, while modeling a business process the business analyst specifies as well the security and compliance requirements the business process should comply to. By pressing a button, these requirements are validated and the results are presented in a graphical format to the business analysis. At the core of SVaaS lies a rigorous and industrially viable approach in which the security validation business logic is handled server-side (SVaaS Server) in the Cloud, while the client-side user interface that business analysts use is handled by a light-weight SVaaS Connector. As proof-of-concept we created a SVaaS prototype in which the SVaaS Server is deployed on the SAP NetWeaver Cloud and two SVaaS Connectors are built to enable two well-known BPMN tools, SAP NetWeaver BPM and Activiti, to consume SVaaS against industrial relevant business processes. Luca Compagna, Pierre Guilleminot, Achim D. Brucker |
ICST | 1 |
| 2013 | A Tool for Supporting Developers in Analyzing the Security of Web-Based Security Protocols
Giancarlo Pellegrino, Luca Compagna, Thomas Morreggia |
ICTSS | 2 |
| 2013 | An authentication flaw in browser-based Single Sign-On protocols: Impact and remediations
Alessandro Armando, Roberto Carbone, Luca Compagna, Jorge Cuéllar, Giancarlo Pellegrino, Alessandro Sorniotti |
Comput. Secur. | 3 |
| 2012 | The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures
Alessandro Armando, Wihem Arsac, Tigran Avanesov, Michele Barletta, Alberto Calvi, Alessandro Cappai, Roberto Carbone, Yannick Chevalier, Luca Compagna, Jorge Cuéllar, Gabriel Erzse, Simone Frau, Marius Minea, Sebastian Mödersheim, David von Oheimb, Giancarlo Pellegrino, Serena Elisa Ponta, Marco Rocchetto, Michaël Rusinowitch, Muhammad Torabi Dashti, Mathieu Turuani, Luca Viganò 0001 |
TACAS | 9 |
| 2011 | Security validation tool for business processesabstractTo evaluate whether a business process (BP) under-design enjoys certain security desiderata is hardly manageable by business analysts without a proper tool support, as the BP runtime environment is highly dynamic, e.g., delegation. We describe a novel security validation tool for BPs that employs model checking for evaluating security-relevant aspects of BPs in dynamic environments and offers accessible user interfaces and apprehensive feedback for business analysts. As proof-of-concept we integrate our tool within SAP NetWeaver Business Process Management. Wihem Arsac, Luca Compagna, Samuel Paul Kaluvuri, Serena Elisa Ponta |
SACMAT | 2 |
| 2011 | From Multiple Credentials to Browser-Based Single Sign-On: Are We More Secure?
Alessandro Armando, Roberto Carbone, Luca Compagna, Jorge Cuéllar, Giancarlo Pellegrino, Alessandro Sorniotti |
SEC | 3 |
| 2011 | Multi-Attacker Protocol Validation
Wihem Arsac, Giampaolo Bella, Xavier Chantry, Luca Compagna |
J. Autom. Reason. | 4 |
| 2009 | Towards Validating Security Protocol Deployment in the WildabstractAs computing technology becomes increasingly pervasive and interconnected, mobility leads to shorter-lasting relationships between end-points with many different security requirements. Also the rapid development of new service landscapes calls for standardized, yet highly flexible security protocols. It has been demonstrated that the increasing number of application contexts of these highly flexible security protocols opens vulnerabilities emerging from the difficulty of assessing the impact of the selected protocol options on the actual security of the relationship established using the protocol. This contribution clearly identifies the underlying problem more generally and establishes the need for run-time on-the-fly verification of security protocol instances considering the actual choice of options and environment assumptions. Extending security protocol verification from the design-time realm into deployment and even run-time generates various challenges. This paper identifies these new challenges and proposes directions for research on solutions. Luca Compagna, Ulrich Flegel, Volkmar Lotz |
COMPSAC (2) | 1 |
| 2007 | LTL Model Checking for Security ProtocolsabstractMost model checking techniques for security protocols make a number of simplifying assumptions on the protocol and/or on its execution environment that prevent their applicability in some important cases. For instance, most techniques assume that communication between honest principals is controlled by a Dolev -Yao intruder, i.e. a malicious agent capable to overhear, divert, and fake messages. Yet we might be interested in establishing the security of a protocol that relies on a less unsecure channel (e.g. a confidential channel provided by some other protocol sitting lower in the protocol stack). In this paper we propose a general model for security protocols based on the set-rewriting formalism that, coupled with the use of LTL, allows for the specification of assumptions on principals and communication channels as well as complex security properties that are normally not handled by state-of-the-art protocol analysers. By using our approach we have been able to formalise all the assumptions required by the ASW protocol for optimistic fair exchange as well as some of its security properties. Besides the previously reported attacks on the protocol, we report a new attack on a patched version of the protocol. Alessandro Armando, Roberto Carbone, Luca Compagna |
CSF | 3 |
| 2007 | How to capture, model, and verify the knowledge of legal, security, and privacy experts: a pattern-based approachabstractLaws set requirements that force organizations to assess the security and privacy of their IT systems and impose the adoption of the implementation of minimal precautionary security measures. Several frameworks have been proposed to deal with thii issue. For instance, purpose-based access control is normally considered a good solution for meeting the requirements of privacy legislation. Yet, understanding why, how, and when such solutions to security and privacy problems have to be deployed is often unanswered. Luca Compagna, Paul El Khoury, Fabio Massacci, Reshma Thomas, Nicola Zannone |
ICAIL | 1 |
| 2005 | The AVISPA Tool for the Automated Validation of Internet Security Protocols and Applications
Alessandro Armando, David A. Basin, Yohan Boichut, Yannick Chevalier, Luca Compagna, Jorge Cuéllar, Paul Hankes Drielsma, Pierre-Cyrille Héam, Olga Kouchnarenko, Jacopo Mantovani, Sebastian Mödersheim, David von Oheimb, Michaël Rusinowitch, Judson Santiago, Mathieu Turuani, Luca Viganò 0001, Laurent Vigneron |
CAV | 5 |
| 2004 | SATMC: A SAT-Based Model Checker for Security Protocols
Alessandro Armando, Luca Compagna |
JELIA | 2 |
| 2004 | Automatic Compilation of Protocol Insecurity Problems into Logic Programming
Alessandro Armando, Luca Compagna, Yuliya Lierler |
JELIA | 2 |
| 2003 | Abstraction-Driven SAT-based Analysis of Security Protocols
Alessandro Armando, Luca Compagna |
SAT | 2 |
| 2002 | The AVISS Security Protocol Analysis Tool
Alessandro Armando, David A. Basin, Mehdi Bouallagui, Yannick Chevalier, Luca Compagna, Sebastian Mödersheim, Michaël Rusinowitch, Mathieu Turuani, Luca Viganò 0001, Laurent Vigneron |
CAV | 5 |
| 2002 | Automatic SAT-Compilation of Protocol Insecurity Problems via Reduction to Planning
Alessandro Armando, Luca Compagna |
FORTE | 2 |