Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
Skip to main content

Showing 1–5 of 5 results for author: Cesarano, C

Searching in archive cs. Search in all archives.
.
  1. arXiv:2407.04442  [pdf, other

    cs.CR

    GoSurf: Identifying Software Supply Chain Attack Vectors in Go

    Authors: Carmine Cesarano, Vivi Andersson, Roberto Natella, Martin Monperrus

    Abstract: In Go, the widespread adoption of open-source software has led to a flourishing ecosystem of third-party dependencies, which are often integrated into critical systems. However, the reuse of dependencies introduces significant supply chain security risks, as a single compromised package can have cascading impacts. Existing supply chain attack taxonomies overlook language-specific features that can… ▽ More

    Submitted 5 July, 2024; originally announced July 2024.

  2. arXiv:2401.05961  [pdf, other

    cs.CR

    Securing an Application Layer Gateway: An Industrial Case Study

    Authors: Carmine Cesarano, Roberto Natella

    Abstract: Application Layer Gateways (ALGs) play a crucial role in securing critical systems, including railways, industrial automation, and defense applications, by segmenting networks at different levels of criticality. However, they require rigorous security testing to prevent software vulnerabilities, not only at the network level but also at the application layer (e.g., deep traffic inspection componen… ▽ More

    Submitted 11 January, 2024; originally announced January 2024.

  3. Security Assessment and Hardening of Fog Computing Systems

    Authors: Carmine Cesarano

    Abstract: In recent years, there has been a shift in computing architectures, moving away from centralized cloud computing towards decentralized edge and fog computing. This shift is driven by factors such as the increasing volume of data generated at the edge, the growing demand for real-time processing and low-latency applications, and the need for improved privacy and data locality. Although this new par… ▽ More

    Submitted 24 August, 2023; originally announced August 2023.

    Comments: 4 pages, Accepted for publication at The 34th IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)

    Journal ref: Proceedings ISSREW2023

  4. arXiv:2303.12817  [pdf, other

    cs.CR cs.OS

    IRIS: a Record and Replay Framework to Enable Hardware-assisted Virtualization Fuzzing

    Authors: Carmine Cesarano, Marcello Cinque, Domenico Cotroneo, Luigi De Simone, Giorgio Farina

    Abstract: Nowadays, industries are looking into virtualization as an effective means to build safe applications, thanks to the isolation it can provide among virtual machines (VMs) running on the same hardware. In this context, a fundamental issue is understanding to what extent the isolation is guaranteed, despite possible (or induced) problems in the virtualization mechanisms. Uncovering such isolation is… ▽ More

    Submitted 22 March, 2023; originally announced March 2023.

    Comments: 13 pages, Accepted for publication at The 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)

  5. Towards Assessing Isolation Properties in Partitioning Hypervisors

    Authors: Carmine Cesarano, Domenico Cotroneo, Luigi De Simone

    Abstract: Partitioning hypervisor solutions are becoming increasingly popular, to ensure stringent security and safety requirements related to isolation between co-hosted applications and to make more efficient use of available hardware resources. However, assessment and certification of isolation requirements remain a challenge and it is not trivial to understand what and how to test to validate these prop… ▽ More

    Submitted 1 September, 2022; originally announced September 2022.

    Journal ref: Proceedings ISSREW2022