<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Publications | Andrea Melis (wildboar)</title>
    <link>/publication/</link>
      <atom:link href="/publication/index.xml" rel="self" type="application/rss+xml" />
    <description>Publications</description>
    <generator>Wowchemy (https://wowchemy.com)</generator><language>en-us</language><lastBuildDate>Tue, 12 Jan 2021 00:00:00 +0000</lastBuildDate>
    <image>
      <url>/images/icon_hu36bdea2b89a1033bee383174eb824552_175602_512x512_fill_lanczos_center_2.png</url>
      <title>Publications</title>
      <link>/publication/</link>
    </image>
    
    <item>
      <title>Microservice Security: A Systematic Literature Review</title>
      <link>/publication/slr_microservice/</link>
      <pubDate>Tue, 12 Jan 2021 00:00:00 +0000</pubDate>
      <guid>/publication/slr_microservice/</guid>
      <description>&lt;p&gt;Microservices is an emerging paradigm for developing distributed systems that is rapidly approaching
widespread adoption. In response to this adoption, an increasing body of work has investigated the relation
between microservices and security. Unfortunately, the literature on this subject does not form a well-defined
corpus: it is spread over many venues, and it consists of contributions that mainly address specific scenarios
or needs. In this work, we conduct a systematic review of the field, gathering 290 relevant publications—at
the time of writing, the largest curated dataset on the topic. We analyse our dataset through (i) publication
metadata, which allows us to chart publication outlets, communities, approaches, and tackled issues; and
(ii) through 20 research questions, which we use to provide an aggregated overview of the literature and to
identify gaps left open. Our study leads to a call for action to address the main open challenges.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>P-SCOR: Integration of Constraint Programming Orchestration and Programmable Data Plane</title>
      <link>/publication/p_scor/</link>
      <pubDate>Sat, 12 Dec 2020 00:00:00 +0000</pubDate>
      <guid>/publication/p_scor/</guid>
      <description>&lt;p&gt;In this manuscript we present an original implementation of network management functions in the context of Software Defined Networking. We demonstrate a full integration of an artificial intelligence driven management, an SDN control plane, and a programmable data plane. Constraint Programming is used to implement a management operating system that accepts high level specifications, via a northbound interface, in terms of operational objective and directives. These are translated in technology-specific constraints and directives for the SDN control plane, leveraging the programmable data plane, which is enriched with functionalities suited to feed data that enable the most effective operation of the “intelligent” control plane, by exploiting the P4 language.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>TechNETium: Atomic Predicates and Model Driven Development to Verify Security Network Policies</title>
      <link>/publication/technetium/</link>
      <pubDate>Sun, 12 Jan 2020 00:00:00 +0000</pubDate>
      <guid>/publication/technetium/</guid>
      <description>&lt;p&gt;Fifth-generation (5G) networks will deliver unprecedented levels of quality of service for online gaming and multimedia-rich social interaction, providing virtual environments optimized for vertical applications through innovative approaches to physical resource management. These techniques must consider security aspects in all phases and at every layer. Trusted communications between individuals and reliable platforms running services for social good depend on the resiliency to network-level attacks such as hijacking and denial-of-service. The verification of topological properties represents a well-suited approach to address these issues in a 5G environment. This paper illustrates moves from formal methods existing in literature, namely atomic predicates (AP) and header space analysis (HSA). It describes a method of integrating AP in Software Defined Network architectures, achieving the same expressive power as HSA without its performance hit, to make topology verification viable for real-time security applications.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Federated Platooning, Insider threat mitigation</title>
      <link>/publication/federated_platooning/</link>
      <pubDate>Tue, 01 Jan 2019 00:00:00 +0000</pubDate>
      <guid>/publication/federated_platooning/</guid>
      <description>&lt;p&gt;Platoon formation is a freight organization system where a group of vehicles follows a predefined trajectory maintaining a desired spatial pattern. Benefits of platooning include fuel savings, reduction of carbon dioxide emissions, and efficient allocation of road capacity. While traditionally platooning has been an exclusive option limited to specific geographical areas managed by a single operator, recent technological developments and EU initiatives are directed at the creation of an international, federated market for platooning, ie, a consortium of platoon operators that collaborate and coordinate their users to constitute freights covering international routes. In this paper, we look at federated platooning from an insiders’ perspective. In our development, first we outline the basic elements of platooning and federation of platooning operators. Then, we provide a comprehensive analysis to identify the possible insiders (employees, users, operators, and federated members) and the threats they pose. Finally, we propose two layered, composable technical solutions to mitigate those threats: a) a decentralized overlay network that regulates the interactions among the stakeholders, useful to mitigate issues linked to data safety and trustworthiness and b) a dynamic federation platform, needed to monitor and interrupt deviant behaviors of federated members.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Cloud-of-Things meets Mobility-as-a-Service: an Insider Threat Perspective</title>
      <link>/publication/overlay_net/</link>
      <pubDate>Tue, 06 Jun 2017 00:00:00 +0000</pubDate>
      <guid>/publication/overlay_net/</guid>
      <description>&lt;p&gt;Mobility-as-a-Service (MaaS) applies the everything-as-a-service paradigm of Cloud Computing to transportation: a MaaS provider offers to its users the dynamic composition of solutions of different travel agencies into a single, consistent interface. Traditionally, transits and data on mobility belong to a scattered plethora of operators. Thus, we argue that the economic model of MaaS is that of federations of providers, each trading its resources to coordinate multi-modal solutions for mobility. Such flexibility comes with many security and privacy concerns, of which insider threat is one of the most prominent. In this paper, we revise and extend previous work where we classified the potential threats of individual operators and markets of federated MaaS providers, proposing appropriate countermeasures to mitigate the problems. In addition, we consider the emerging case of Cloud-of-Things (CoT) for mobility, i.e., networks of ubiquitous, pervasive devices that provide real-time data on objects and people. Automation and pervasiveness of CoT make an additional attack surface for insiders. In an effort to limit such phenomenon, we present an overlay networking architecture, based on gossip protocols, that lets users share information on mobility with each other. A peculiarity of the architecture is that it both constrains the quality and quantity of data obtainable by insiders, optimizing the routing of requests to involve only users that are able to answer them.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Insider Threats in Emerging Mobility-as-a-Service Scenarios</title>
      <link>/publication/insider_threat/</link>
      <pubDate>Thu, 12 Jan 2017 00:00:00 +0000</pubDate>
      <guid>/publication/insider_threat/</guid>
      <description>&lt;p&gt;Mobility as a Service (MaaS) applies the everything-as-a-service paradigm of Cloud Computing to transportation: a MaaS provider offers to its users the dynamic composition of solutions of different travel agencies into a single, consistent interface. Traditionally, transits and data on mobility belong to a scattered plethora of operators. Thus, we argue that the economic model of MaaS is that of federations of providers, each trading its resources to coordinate multi-modal solutions for mobility. Such flexibility comes with many security and privacy concerns, of which insider threat is one of the most prominent. In this paper, we follow a tiered structure — from individual operators to markets of federated MaaS providers — to classify the potential threats of each tier and propose the appropriate countermeasures, in an effort to mitigate the problems.&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>
