7 papers
Holoscope: Open and Lightweight Telescope & Honeypot Platform
Andrea Sordello, Marco Mellia, Idilio Drago +7
The complexity and scale of Internet attacks call for distributed, cooperative observatories capable of monitoring malicious traffic across diverse networks. Holoscope is an open,…
Dense Contexts Are Hard Contexts: Lexical Density Limits Effective Context in LLMs
Giovanni Dettori, Matteo Boffa, Danilo Giordano +2
Input length and the position of relevant information are widely cited as the primary causes of degraded LLM long-context performance. Here, we study lexical density -- the rate at…
Improving Generalization on Cybersecurity Tasks with Multi-Modal Contrastive Learning
Jianan Huang, Rodolfo V. Valentim, Luca Vassio +4
The use of ML in cybersecurity has long been impaired by generalization issues: Models that work well in controlled scenarios fail to maintain performance in production. The root c…
Towards Agentic Honeynet Configuration
Federico Mirra, Matteo Boffa, Idilio Drago +2
Honeypots are deception systems that emulate vulnerable services to collect threat intelligence. While deploying many honeypots increases the opportunity to observe attacker behavi…
ARBITER: AI-Driven Filtering for Role-Based Access Control
Michele Lorenzo, Idilio Drago, Dario Salvadori +1
Role-Based Access Control (RBAC) struggles to adapt to dynamic enterprise environments with documents that contain information that cannot be disclosed to specific user groups. As…
ChamaleoNet: Programmable Passive Probe for Enhanced Visibility on Erroneous Traffic
Zhihao Wang, Alessandro Cornacchia, Andrea Bianco +4
Traffic visibility remains a key component for management and security operations. Observing erroneous traffic, i.e., unanswered requests or error messages, is fundamental to detec…