most citedNever Trust Your Victim: Weaponizing Vulnerabilities in Security Scanners

2 citations · 3 across the 3 of their papers we have counts for

collaborators

5 papers

cs.CR2020

Why Charles Can Pen-test: an Evolutionary Approach to Vulnerability Testing

Gabriele Costa, Andrea Valenza

Discovering vulnerabilities in applications of real-world complexity is a daunting task: a vulnerability may affect a single line of code, and yet it compromises the security of th…

cs.CR2020

Private-Yet-Verifiable Contact Tracing

Andrea Canidio, Gabriele Costa, Letterio Galletta

We propose PrYVeCT, a private-yet-verifiable contact tracing system. PrYVeCT works also as an authorization framework allowing for the definition of fine-grained policies, which a…

cs.CR20202 cited

Never Trust Your Victim: Weaponizing Vulnerabilities in Security Scanners

Andrea Valenza, Gabriele Costa, Alessandro Armando

The first step of every attack is reconnaissance, i.e., to acquire information about the target. A common belief is that there is almost no risk in scanning a target from a remote…

cs.CR2020

WAF-A-MoLE: Evading Web Application Firewalls through Adversarial Machine Learning

Luca Demetrio, Andrea Valenza, Gabriele Costa +1

Web Application Firewalls are widely used in production environments to mitigate security threats like SQL injections. Many industrial products rely on signature-based techniques,…

cs.CR20121 cited

Metric-Aware Secure Service Orchestration

Gabriele Costa, Fabio Martinelli, Artsiom Yautsiukhin

Secure orchestration is an important concern in the internet of service. Next to providing the required functionality the composite services must also provide a reasonable level of…