Dear Dissemination Committee,
we have about to publish a paper for which we would like to acknowledge
the SPARTA project.
Please, find the version that we plan to submit in attachment and a
brief description of the content, the venue and the relation with the
activities of WP6 below.
Please let us know if you have any objections or comments.
Best regards
Gabriele Costa
===
Title: WAF-A-MoLE: Evading Web Application Firewalls through Adversarial
Machine Learning
Venue: ACM Symposium on Applied Computing
Relationship with SPARTA: The paper presents a a technique to evade
machine learning-based web application firewalls (WAFs). This work shows
that ML WAFs are not reliable in discriminating between attack payloads
and harmless traffic. The activity is related to the identification and
evaluation of the state-of-the-art technologies adopted in the IIs.
Dear All,
We plan to submit Sparta and Safair relevant SOTA type of paper (draft
attached) for the DisA workshop (I co-organize) at ICCS 2020 in Amsterdam:
http://disa.kssk.pwr.edu.pl/https://www.iccs-meeting.org/iccs2020/
Title: Machine Learning - the results are not the only thing that matters!
What about security, explainability and fairness?
By: Choras, Pawlicki, Puchalski and Kozik.
The paper uses ITTI text relevant for D7.2.
If accepted we plan to acknowledge SPARTA.
Kind Regards,
Prof. Michal Choras
-------------------------- Wiadomość oryginalna --------------------------
Temat: [SPARTA - bodies.dissemination-committee] Request for SPARTA
acknowledgment in accepted paper
Od: "Gabriele Costa" <gabriele.costa(a)imtlucca.it>
Data: 27 Listopada 2019, 3:48 pm, Śr
Do: bodies.dissemination-committee(a)internal.sparta.eu
--------------------------------------------------------------------------
Dear Dissemination Committee,
we have about to publish a paper for which we would like to acknowledge
the SPARTA project.
Please, find the version that we plan to submit in attachment and a
brief description of the content, the venue and the relation with the
activities of WP6 below.
Please let us know if you have any objections or comments.
Best regards
Gabriele Costa
===
Title: WAF-A-MoLE: Evading Web Application Firewalls through Adversarial
Machine Learning
Venue: ACM Symposium on Applied Computing
Relationship with SPARTA: The paper presents a a technique to evade
machine learning-based web application firewalls (WAFs). This work shows
that ML WAFs are not reliable in discriminating between attack payloads
and harmless traffic. The activity is related to the identification and
evaluation of the state-of-the-art technologies adopted in the IIs.
--
bodies.dissemination-committee mailing list
bodies.dissemination-committee(a)server.sparta.eu
http://server.sparta.eu/cgi-bin/mailman/listinfo/bodies.dissemination-commi…
Dear Dissemination Committee,
we have about to publish four papers for which we would like to
acknowledge the SPARTA project.
Please, find the versions that we plan to submit in attachment and a
brief description of the content, the venue and the relation with the
activities of WP6 below.
Please let us know if you have any objections or comments.
Best regards
Gabriele Costa
===
Title: Natural Projection as Partial Model Checking
Venue: Journal of Automated Reasoning
Relationship with SPARTA: The paper presents a theoretical result
showing that partial model checking and natural projection are
equivalent. Based on this result we developed an algorithm and a tool
for the automatic synthesis of controllers and sub-modules. This
technique is well integrated in WP6 and, in particular, in Task 6.3 as
it may serve as for the generation of orchestrators directly from high
level security policies.
Title: WAF-A-MoLE: An adversarial tool for assessing ML-based WAFs
Venue: SoftwareX
Relationship with SPARTA: The paper presents a tool for automatically
generating adversarial attacks able to bypass ML-based web application
firewalls (WAFs). WAFs are often deployed in modern II as a line of
protection against injection attacks. This work shows that using ML for
this purpose is not secure in general. The activity is related to the
identification and evaluation of the state-of-the-art technologies
adopted in the IIs.
Title: A Survey on Multi-Factor Authentication for Online Banking in the
Wild
Venue: Computers and Security
Relationship with SPARTA: The paper presents a survey on the
multi-factor authentication platforms used by a number of banks
worldwide. Also, we carried out a systematic review of regulations and
guidelines and we evaluated how the MFA solutions cope with them. This
activity is strongly related to WP6 as we carried out an in depth
evaluation of the service infrastructures used for implementing the
authentication of customers in the bank sector.
Title: Building Next Generation Cyber Ranges with CRACK
Venue: Computers and Security
Relationship with SPARTA: The paper introduces a virtual infrastructure
implementing a cyber range. Its purpose is to run virtual
infrastructures where security training exercises can be executed. The
technology developed for this purpose is the same that will support the
orchestration framework that CINI will provide in Task 6.3
===
Dear all,
we have submitted a research paper entitled "Automated Security Analysis of IoT Software Updates" that has been accepted in the 13th WISTP International Conference on Information Security Theory and Practice (http://www.wistp.org/program/).
The paper presents a new automated software analysis framework for systematically verifying the security of IoT applications contained in software updates w.r.t. a given security policy.
Therefore, this paper is in line with WP6 and, in particular, with Task 6.1 on Securing Operating System Software.
Please find the prefinal version of our paper attached to this email.
If the dissemination committee raises no objections, we would like to acknowledge the SPARTA project.
Best regards,
Luca Verderame
--
Luca Verderame
*************************************************
Computer Security Lab
DIBRIS - University of Genova
Via Dodecaneso, 35, 16146, Genova, Italy.
**************************************************
--
The information transmitted is intended for the person or entity to which it is addressed and may contain confidential and/or privileged material.
Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited.
If you received this in error, please contact the sender and delete the material from any computer.
Dear Sirs,
me, Gianluca Roascio and Paolo Prinetto, are submitting the paper “A FPGA-base Control-Flow Integrity Solution for Securing Bare-Metal Embedded Systems” to the International Symposium on Hardware Oriented Security and Trust (HOST) 2020
Please find the paper in attachment.
If the paper will be accepted and no objections will be raised by diss. committee, we would like to acknowledge SPARTA.
The notification of acceptance is on Jan 30.
Best regards,
Nicolò Maunero