BibTeX records: Giancarlo Pellegrino

download as .bib file

@inproceedings{DBLP:conf/acsac/StivalaAMGFP23,
  author       = {Giada Stivala and
                  Sahar Abdelnabi and
                  Andrea Mengascini and
                  Mariano Graziano and
                  Mario Fritz and
                  Giancarlo Pellegrino},
  title        = {From Attachments to {SEO:} Click Here to Learn More about Clickbait
                  PDFs!},
  booktitle    = {Annual Computer Security Applications Conference, {ACSAC} 2023, Austin,
                  TX, USA, December 4-8, 2023},
  pages        = {14--28},
  publisher    = {{ACM}},
  year         = {2023},
  url          = {https://doi.org/10.1145/3627106.3627172},
  doi          = {10.1145/3627106.3627172},
  timestamp    = {Sun, 10 Dec 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/acsac/StivalaAMGFP23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/KhodayariP23,
  author       = {Soheil Khodayari and
                  Giancarlo Pellegrino},
  title        = {It's {(DOM)} Clobbering Time: Attack Techniques, Prevalence, and Defenses},
  booktitle    = {44th {IEEE} Symposium on Security and Privacy, {SP} 2023, San Francisco,
                  CA, USA, May 21-25, 2023},
  pages        = {1041--1058},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/SP46215.2023.10179403},
  doi          = {10.1109/SP46215.2023.10179403},
  timestamp    = {Thu, 27 Jul 2023 08:17:10 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/KhodayariP23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/RautenstrauchPS23,
  author       = {Jannis Rautenstrauch and
                  Giancarlo Pellegrino and
                  Ben Stock},
  title        = {The Leaky Web: Automated Discovery of Cross-Site Information Leaks
                  in Browsers and the Web},
  booktitle    = {44th {IEEE} Symposium on Security and Privacy, {SP} 2023, San Francisco,
                  CA, USA, May 21-25, 2023},
  pages        = {2744--2760},
  publisher    = {{IEEE}},
  year         = {2023},
  url          = {https://doi.org/10.1109/SP46215.2023.10179311},
  doi          = {10.1109/SP46215.2023.10179311},
  timestamp    = {Thu, 27 Jul 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/RautenstrauchPS23.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-2308-01273,
  author       = {Giada Stivala and
                  Sahar Abdelnabi and
                  Andrea Mengascini and
                  Mariano Graziano and
                  Mario Fritz and
                  Giancarlo Pellegrino},
  title        = {A Large-Scale Study of Phishing {PDF} Documents},
  journal      = {CoRR},
  volume       = {abs/2308.01273},
  year         = {2023},
  url          = {https://doi.org/10.48550/arXiv.2308.01273},
  doi          = {10.48550/ARXIV.2308.01273},
  eprinttype    = {arXiv},
  eprint       = {2308.01273},
  timestamp    = {Mon, 21 Aug 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-2308-01273.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/KhodayariP22,
  author       = {Soheil Khodayari and
                  Giancarlo Pellegrino},
  title        = {The State of the SameSite: Studying the Usage, Effectiveness, and
                  Adequacy of SameSite Cookies},
  booktitle    = {43rd {IEEE} Symposium on Security and Privacy, {SP} 2022, San Francisco,
                  CA, USA, May 22-26, 2022},
  pages        = {1590--1607},
  publisher    = {{IEEE}},
  year         = {2022},
  url          = {https://doi.org/10.1109/SP46214.2022.9833637},
  doi          = {10.1109/SP46214.2022.9833637},
  timestamp    = {Thu, 21 Sep 2023 15:57:27 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/KhodayariP22.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@proceedings{DBLP:conf/dimva/2022,
  editor       = {Lorenzo Cavallaro and
                  Daniel Gruss and
                  Giancarlo Pellegrino and
                  Giorgio Giacinto},
  title        = {Detection of Intrusions and Malware, and Vulnerability Assessment
                  - 19th International Conference, {DIMVA} 2022, Cagliari, Italy, June
                  29 - July 1, 2022, Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {13358},
  publisher    = {Springer},
  year         = {2022},
  url          = {https://doi.org/10.1007/978-3-031-09484-2},
  doi          = {10.1007/978-3-031-09484-2},
  isbn         = {978-3-031-09483-5},
  timestamp    = {Fri, 01 Jul 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/dimva/2022.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/raid/LikajKP21,
  author       = {Xhelal Likaj and
                  Soheil Khodayari and
                  Giancarlo Pellegrino},
  editor       = {Leyla Bilge and
                  Tudor Dumitras},
  title        = {Where We Stand (or Fall): An Analysis of {CSRF} Defenses in Web Frameworks},
  booktitle    = {{RAID} '21: 24th International Symposium on Research in Attacks, Intrusions
                  and Defenses, San Sebastian, Spain, October 6-8, 2021},
  pages        = {370--385},
  publisher    = {{ACM}},
  year         = {2021},
  url          = {https://doi.org/10.1145/3471621.3471846},
  doi          = {10.1145/3471621.3471846},
  timestamp    = {Fri, 08 Oct 2021 09:46:25 +0200},
  biburl       = {https://dblp.org/rec/conf/raid/LikajKP21.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/ErikssonPS21,
  author       = {Benjamin Eriksson and
                  Giancarlo Pellegrino and
                  Andrei Sabelfeld},
  title        = {Black Widow: Blackbox Data-driven Web Scanning},
  booktitle    = {42nd {IEEE} Symposium on Security and Privacy, {SP} 2021, San Francisco,
                  CA, USA, 24-27 May 2021},
  pages        = {1125--1142},
  publisher    = {{IEEE}},
  year         = {2021},
  url          = {https://doi.org/10.1109/SP40001.2021.00022},
  doi          = {10.1109/SP40001.2021.00022},
  timestamp    = {Thu, 21 Sep 2023 15:57:26 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/ErikssonPS21.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/uss/KhodayariP21,
  author       = {Soheil Khodayari and
                  Giancarlo Pellegrino},
  editor       = {Michael D. Bailey and
                  Rachel Greenstadt},
  title        = {{JAW:} Studying Client-side {CSRF} with Hybrid Property Graphs and
                  Declarative Traversals},
  booktitle    = {30th {USENIX} Security Symposium, {USENIX} Security 2021, August 11-13,
                  2021},
  pages        = {2525--2542},
  publisher    = {{USENIX} Association},
  year         = {2021},
  url          = {https://www.usenix.org/conference/usenixsecurity21/presentation/khodayari},
  timestamp    = {Mon, 20 Nov 2023 08:57:49 +0100},
  biburl       = {https://dblp.org/rec/conf/uss/KhodayariP21.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@proceedings{DBLP:conf/dimva/2021,
  editor       = {Leyla Bilge and
                  Lorenzo Cavallaro and
                  Giancarlo Pellegrino and
                  Nuno Neves},
  title        = {Detection of Intrusions and Malware, and Vulnerability Assessment
                  - 18th International Conference, {DIMVA} 2021, Virtual Event, July
                  14-16, 2021, Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {12756},
  publisher    = {Springer},
  year         = {2021},
  url          = {https://doi.org/10.1007/978-3-030-80825-9},
  doi          = {10.1007/978-3-030-80825-9},
  isbn         = {978-3-030-80824-2},
  timestamp    = {Tue, 13 Jul 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/dimva/2021.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ndss/StivalaP20,
  author       = {Giada Stivala and
                  Giancarlo Pellegrino},
  title        = {Deceptive Previews: {A} Study of the Link Preview Trustworthiness
                  in Social Platforms},
  booktitle    = {27th Annual Network and Distributed System Security Symposium, {NDSS}
                  2020, San Diego, California, USA, February 23-26, 2020},
  publisher    = {The Internet Society},
  year         = {2020},
  url          = {https://www.ndss-symposium.org/ndss-paper/deceptive-previews-a-study-of-the-link-preview-trustworthiness-in-social-platforms/},
  timestamp    = {Mon, 01 Feb 2021 08:42:10 +0100},
  biburl       = {https://dblp.org/rec/conf/ndss/StivalaP20.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sac/KochSJP20,
  author       = {Simon Koch and
                  Tim Sauer and
                  Martin Johns and
                  Giancarlo Pellegrino},
  editor       = {Chih{-}Cheng Hung and
                  Tom{\'{a}}s Cern{\'{y}} and
                  Dongwan Shin and
                  Alessio Bechini},
  title        = {Raccoon: automated verification of guarded race conditions in web
                  applications},
  booktitle    = {{SAC} '20: The 35th {ACM/SIGAPP} Symposium on Applied Computing, online
                  event, [Brno, Czech Republic], March 30 - April 3, 2020},
  pages        = {1678--1687},
  publisher    = {{ACM}},
  year         = {2020},
  url          = {https://doi.org/10.1145/3341105.3373855},
  doi          = {10.1145/3341105.3373855},
  timestamp    = {Sat, 30 Sep 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/sac/KochSJP20.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/ChouTP20,
  author       = {Edward Chou and
                  Florian Tram{\`{e}}r and
                  Giancarlo Pellegrino},
  title        = {SentiNet: Detecting Localized Universal Attacks Against Deep Learning
                  Systems},
  booktitle    = {2020 {IEEE} Security and Privacy Workshops, {SP} Workshops, San Francisco,
                  CA, USA, May 21, 2020},
  pages        = {48--54},
  publisher    = {{IEEE}},
  year         = {2020},
  url          = {https://doi.org/10.1109/SPW50608.2020.00025},
  doi          = {10.1109/SPW50608.2020.00025},
  timestamp    = {Thu, 21 Sep 2023 16:11:10 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/ChouTP20.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/ZhaoZDPL20,
  author       = {Qingchuan Zhao and
                  Chaoshun Zuo and
                  Brendan Dolan{-}Gavitt and
                  Giancarlo Pellegrino and
                  Zhiqiang Lin},
  title        = {Automatic Uncovering of Hidden Behaviors From Input Validation in
                  Mobile Apps},
  booktitle    = {2020 {IEEE} Symposium on Security and Privacy, {SP} 2020, San Francisco,
                  CA, USA, May 18-21, 2020},
  pages        = {1106--1120},
  publisher    = {{IEEE}},
  year         = {2020},
  url          = {https://doi.org/10.1109/SP40000.2020.00072},
  doi          = {10.1109/SP40000.2020.00072},
  timestamp    = {Thu, 21 Sep 2023 15:57:24 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/ZhaoZDPL20.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ccs/TramerDRPB19,
  author       = {Florian Tram{\`{e}}r and
                  Pascal Dupr{\'{e}} and
                  Gili Rusak and
                  Giancarlo Pellegrino and
                  Dan Boneh},
  editor       = {Lorenzo Cavallaro and
                  Johannes Kinder and
                  XiaoFeng Wang and
                  Jonathan Katz},
  title        = {AdVersarial: Perceptual Ad Blocking meets Adversarial Machine Learning},
  booktitle    = {Proceedings of the 2019 {ACM} {SIGSAC} Conference on Computer and
                  Communications Security, {CCS} 2019, London, UK, November 11-15, 2019},
  pages        = {2005--2021},
  publisher    = {{ACM}},
  year         = {2019},
  url          = {https://doi.org/10.1145/3319535.3354222},
  doi          = {10.1145/3319535.3354222},
  timestamp    = {Mon, 28 Aug 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/ccs/TramerDRPB19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ndss/ZhaoZPL19,
  author       = {Qingchuan Zhao and
                  Chaoshun Zuo and
                  Giancarlo Pellegrino and
                  Zhiqiang Lin},
  title        = {Geo-locating Drivers: {A} Study of Sensitive Data Leakage in Ride-Hailing
                  Services},
  booktitle    = {26th Annual Network and Distributed System Security Symposium, {NDSS}
                  2019, San Diego, California, USA, February 24-27, 2019},
  publisher    = {The Internet Society},
  year         = {2019},
  url          = {https://www.ndss-symposium.org/ndss-paper/geo-locating-drivers-a-study-of-sensitive-data-leakage-in-ride-hailing-services/},
  timestamp    = {Mon, 01 Feb 2021 08:42:22 +0100},
  biburl       = {https://dblp.org/rec/conf/ndss/ZhaoZPL19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/EskandarianCBBF19,
  author       = {Saba Eskandarian and
                  Jonathan Cogan and
                  Sawyer Birnbaum and
                  Peh Chang Wei Brandon and
                  Dillon Franke and
                  Forest Fraser and
                  Gaspar Garcia Jr. and
                  Eric Gong and
                  Hung T. Nguyen and
                  Taresh K. Sethi and
                  Vishal Subbiah and
                  Michael Backes and
                  Giancarlo Pellegrino and
                  Dan Boneh},
  title        = {Fidelius: Protecting User Secrets from Compromised Browsers},
  booktitle    = {2019 {IEEE} Symposium on Security and Privacy, {SP} 2019, San Francisco,
                  CA, USA, May 19-23, 2019},
  pages        = {264--280},
  publisher    = {{IEEE}},
  year         = {2019},
  url          = {https://doi.org/10.1109/SP.2019.00036},
  doi          = {10.1109/SP.2019.00036},
  timestamp    = {Wed, 16 Oct 2019 14:14:51 +0200},
  biburl       = {https://dblp.org/rec/conf/sp/EskandarianCBBF19.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/eurosp/SpeicherSKSP0018,
  author       = {Patrick Speicher and
                  Marcel Steinmetz and
                  Robert K{\"{u}}nnemann and
                  Milivoj Simeonovski and
                  Giancarlo Pellegrino and
                  J{\"{o}}rg Hoffmann and
                  Michael Backes},
  title        = {Formally Reasoning about the Cost and Efficacy of Securing the Email
                  Infrastructure},
  booktitle    = {2018 {IEEE} European Symposium on Security and Privacy, EuroS{\&}P
                  2018, London, United Kingdom, April 24-26, 2018},
  pages        = {77--91},
  publisher    = {{IEEE}},
  year         = {2018},
  url          = {https://doi.org/10.1109/EuroSP.2018.00014},
  doi          = {10.1109/EUROSP.2018.00014},
  timestamp    = {Wed, 16 Oct 2019 14:14:55 +0200},
  biburl       = {https://dblp.org/rec/conf/eurosp/SpeicherSKSP0018.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ndss/StockPL0R18,
  author       = {Ben Stock and
                  Giancarlo Pellegrino and
                  Frank Li and
                  Michael Backes and
                  Christian Rossow},
  title        = {Didn't You Hear Me? - Towards More Successful Web Vulnerability Notifications},
  booktitle    = {25th Annual Network and Distributed System Security Symposium, {NDSS}
                  2018, San Diego, California, USA, February 18-21, 2018},
  publisher    = {The Internet Society},
  year         = {2018},
  url          = {https://www.ndss-symposium.org/wp-content/uploads/2018/02/ndss2018\_01B-1\_Stock\_paper.pdf},
  timestamp    = {Thu, 15 Jun 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/ndss/StockPL0R18.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sp/OltroggeDSAFRPB18,
  author       = {Marten Oltrogge and
                  Erik Derr and
                  Christian Stransky and
                  Yasemin Acar and
                  Sascha Fahl and
                  Christian Rossow and
                  Giancarlo Pellegrino and
                  Sven Bugiel and
                  Michael Backes},
  title        = {The Rise of the Citizen Developer: Assessing the Security Impact of
                  Online App Generators},
  booktitle    = {2018 {IEEE} Symposium on Security and Privacy, {SP} 2018, Proceedings,
                  21-23 May 2018, San Francisco, California, {USA}},
  pages        = {634--647},
  publisher    = {{IEEE} Computer Society},
  year         = {2018},
  url          = {https://doi.org/10.1109/SP.2018.00005},
  doi          = {10.1109/SP.2018.00005},
  timestamp    = {Fri, 24 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/sp/OltroggeDSAFRPB18.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1809-04774,
  author       = {Saba Eskandarian and
                  Jonathan Cogan and
                  Sawyer Birnbaum and
                  Peh Chang Wei Brandon and
                  Dillon Franke and
                  Forest Fraser and
                  Gaspar Garcia Jr. and
                  Eric Gong and
                  Hung T. Nguyen and
                  Taresh K. Sethi and
                  Vishal Subbiah and
                  Michael Backes and
                  Giancarlo Pellegrino and
                  Dan Boneh},
  title        = {Fidelius: Protecting User Secrets from Compromised Browsers},
  journal      = {CoRR},
  volume       = {abs/1809.04774},
  year         = {2018},
  url          = {http://arxiv.org/abs/1809.04774},
  eprinttype    = {arXiv},
  eprint       = {1809.04774},
  timestamp    = {Fri, 05 Oct 2018 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1809-04774.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1811-03194,
  author       = {Florian Tram{\`{e}}r and
                  Pascal Dupr{\'{e}} and
                  Gili Rusak and
                  Giancarlo Pellegrino and
                  Dan Boneh},
  title        = {Ad-versarial: Defeating Perceptual Ad-Blocking},
  journal      = {CoRR},
  volume       = {abs/1811.03194},
  year         = {2018},
  url          = {http://arxiv.org/abs/1811.03194},
  eprinttype    = {arXiv},
  eprint       = {1811.03194},
  timestamp    = {Thu, 22 Nov 2018 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1811-03194.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1812-00292,
  author       = {Edward Chou and
                  Florian Tram{\`{e}}r and
                  Giancarlo Pellegrino and
                  Dan Boneh},
  title        = {SentiNet: Detecting Physical Attacks Against Deep Learning Systems},
  journal      = {CoRR},
  volume       = {abs/1812.00292},
  year         = {2018},
  url          = {http://arxiv.org/abs/1812.00292},
  eprinttype    = {arXiv},
  eprint       = {1812.00292},
  timestamp    = {Tue, 01 Jan 2019 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1812-00292.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ccs/PellegrinoJ0BR17,
  author       = {Giancarlo Pellegrino and
                  Martin Johns and
                  Simon Koch and
                  Michael Backes and
                  Christian Rossow},
  editor       = {Bhavani Thuraisingham and
                  David Evans and
                  Tal Malkin and
                  Dongyan Xu},
  title        = {Deemon: Detecting {CSRF} with Dynamic Analysis and Property Graphs},
  booktitle    = {Proceedings of the 2017 {ACM} {SIGSAC} Conference on Computer and
                  Communications Security, {CCS} 2017, Dallas, TX, USA, October 30 -
                  November 03, 2017},
  pages        = {1757--1771},
  publisher    = {{ACM}},
  year         = {2017},
  url          = {https://doi.org/10.1145/3133956.3133959},
  doi          = {10.1145/3133956.3133959},
  timestamp    = {Mon, 26 Jun 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/ccs/PellegrinoJ0BR17.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/www/SimeonovskiPR017,
  author       = {Milivoj Simeonovski and
                  Giancarlo Pellegrino and
                  Christian Rossow and
                  Michael Backes},
  editor       = {Rick Barrett and
                  Rick Cummings and
                  Eugene Agichtein and
                  Evgeniy Gabrilovich},
  title        = {Who Controls the Internet?: Analyzing Global Threats using Property
                  Graph Traversals},
  booktitle    = {Proceedings of the 26th International Conference on World Wide Web,
                  {WWW} 2017, Perth, Australia, April 3-7, 2017},
  pages        = {647--656},
  publisher    = {{ACM}},
  year         = {2017},
  url          = {https://doi.org/10.1145/3038912.3052587},
  doi          = {10.1145/3038912.3052587},
  timestamp    = {Tue, 16 Aug 2022 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/www/SimeonovskiPR017.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/corr/abs-1708-08786,
  author       = {Giancarlo Pellegrino and
                  Martin Johns and
                  Simon Koch and
                  Michael Backes and
                  Christian Rossow},
  title        = {Deemon: Detecting {CSRF} with Dynamic Analysis and Property Graphs},
  journal      = {CoRR},
  volume       = {abs/1708.08786},
  year         = {2017},
  url          = {http://arxiv.org/abs/1708.08786},
  eprinttype    = {arXiv},
  eprint       = {1708.08786},
  timestamp    = {Mon, 13 Aug 2018 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/corr/abs-1708-08786.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ccs/StockPRJ016,
  author       = {Ben Stock and
                  Giancarlo Pellegrino and
                  Christian Rossow and
                  Martin Johns and
                  Michael Backes},
  editor       = {Edgar R. Weippl and
                  Stefan Katzenbeisser and
                  Christopher Kruegel and
                  Andrew C. Myers and
                  Shai Halevi},
  title        = {{POSTER:} Mapping the Landscape of Large-Scale Vulnerability Notifications},
  booktitle    = {Proceedings of the 2016 {ACM} {SIGSAC} Conference on Computer and
                  Communications Security, Vienna, Austria, October 24-28, 2016},
  pages        = {1787--1789},
  publisher    = {{ACM}},
  year         = {2016},
  url          = {https://doi.org/10.1145/2976749.2989057},
  doi          = {10.1145/2976749.2989057},
  timestamp    = {Tue, 10 Nov 2020 20:00:49 +0100},
  biburl       = {https://dblp.org/rec/conf/ccs/StockPRJ016.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/raid/PellegrinoCBR16,
  author       = {Giancarlo Pellegrino and
                  Onur Catakoglu and
                  Davide Balzarotti and
                  Christian Rossow},
  editor       = {Fabian Monrose and
                  Marc Dacier and
                  Gregory Blanc and
                  Joaqu{\'{\i}}n Garc{\'{\i}}a{-}Alfaro},
  title        = {Uses and Abuses of Server-Side Requests},
  booktitle    = {Research in Attacks, Intrusions, and Defenses - 19th International
                  Symposium, {RAID} 2016, Paris, France, September 19-21, 2016, Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {9854},
  pages        = {393--414},
  publisher    = {Springer},
  year         = {2016},
  url          = {https://doi.org/10.1007/978-3-319-45719-2\_18},
  doi          = {10.1007/978-3-319-45719-2\_18},
  timestamp    = {Fri, 27 Dec 2019 21:24:31 +0100},
  biburl       = {https://dblp.org/rec/conf/raid/PellegrinoCBR16.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/uss/StockPRJ016,
  author       = {Ben Stock and
                  Giancarlo Pellegrino and
                  Christian Rossow and
                  Martin Johns and
                  Michael Backes},
  editor       = {Thorsten Holz and
                  Stefan Savage},
  title        = {Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability
                  Notification},
  booktitle    = {25th {USENIX} Security Symposium, {USENIX} Security 16, Austin, TX,
                  USA, August 10-12, 2016},
  pages        = {1015--1032},
  publisher    = {{USENIX} Association},
  year         = {2016},
  url          = {https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/stock},
  timestamp    = {Mon, 01 Feb 2021 08:43:18 +0100},
  biburl       = {https://dblp.org/rec/conf/uss/StockPRJ016.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/raid/PellegrinoTBR15,
  author       = {Giancarlo Pellegrino and
                  Constantin Tsch{\"{u}}rtz and
                  Eric Bodden and
                  Christian Rossow},
  editor       = {Herbert Bos and
                  Fabian Monrose and
                  Gregory Blanc},
  title        = {j{\"{A}}k: Using Dynamic Analysis to Crawl and Test Modern Web
                  Applications},
  booktitle    = {Research in Attacks, Intrusions, and Defenses - 18th International
                  Symposium, {RAID} 2015, Kyoto, Japan, November 2-4, 2015, Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {9404},
  pages        = {295--316},
  publisher    = {Springer},
  year         = {2015},
  url          = {https://doi.org/10.1007/978-3-319-26362-5\_14},
  doi          = {10.1007/978-3-319-26362-5\_14},
  timestamp    = {Tue, 01 Jun 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/raid/PellegrinoTBR15.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/uss/PellegrinoBWS15,
  author       = {Giancarlo Pellegrino and
                  Davide Balzarotti and
                  Stefan Winter and
                  Neeraj Suri},
  editor       = {Jaeyeon Jung and
                  Thorsten Holz},
  title        = {In the Compression Hornet's Nest: {A} Security Study of Data Compression
                  in Network Services},
  booktitle    = {24th {USENIX} Security Symposium, {USENIX} Security 15, Washington,
                  D.C., USA, August 12-14, 2015},
  pages        = {801--816},
  publisher    = {{USENIX} Association},
  year         = {2015},
  url          = {https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/pellegrino},
  timestamp    = {Mon, 01 Feb 2021 08:42:57 +0100},
  biburl       = {https://dblp.org/rec/conf/uss/PellegrinoBWS15.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/woot/PellegrinoRRSW15,
  author       = {Giancarlo Pellegrino and
                  Christian Rossow and
                  Fabrice J. Ryba and
                  Thomas C. Schmidt and
                  Matthias W{\"{a}}hlisch},
  editor       = {Aur{\'{e}}lien Francillon and
                  Thomas Ptacek},
  title        = {Cashing Out the Great Cannon? On Browser-Based DDoS Attacks and Economics},
  booktitle    = {9th {USENIX} Workshop on Offensive Technologies, {WOOT} '15, Washington,
                  DC, USA, August 10-11, 2015},
  publisher    = {{USENIX} Association},
  year         = {2015},
  url          = {https://www.usenix.org/conference/woot15/workshop-program/presentation/pellegrino},
  timestamp    = {Mon, 01 Feb 2021 08:41:51 +0100},
  biburl       = {https://dblp.org/rec/conf/woot/PellegrinoRRSW15.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@incollection{DBLP:books/daglib/p/MikkelsenDGJGNPPSSZ15,
  author       = {Gert L{\ae}ss{\o}e Mikkelsen and
                  Kasper Damg{\aa}rd and
                  Hans Guldager and
                  Jonas Lindstr{\o}m Jensen and
                  Jesus Luna Garcia and
                  Janus Dam Nielsen and
                  Pascal Paillier and
                  Giancarlo Pellegrino and
                  Michael Bladt Stausholm and
                  Neeraj Suri and
                  Heng Zhang},
  editor       = {Kai Rannenberg and
                  Jan Camenisch and
                  Ahmad Sabouri},
  title        = {Technical Implementation and Feasibility},
  booktitle    = {Attribute-based Credentials for Trust: Identity in the Information
                  Society},
  pages        = {255--317},
  publisher    = {Springer},
  year         = {2015},
  url          = {https://doi.org/10.1007/978-3-319-14439-9\_9},
  doi          = {10.1007/978-3-319-14439-9\_9},
  timestamp    = {Sun, 25 Oct 2020 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/books/daglib/p/MikkelsenDGJGNPPSSZ15.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icete/Vateva-GurovaLP14,
  author       = {Tsvetoslava Vateva{-}Gurova and
                  Jesus Luna and
                  Giancarlo Pellegrino and
                  Neeraj Suri},
  editor       = {Mohammad S. Obaidat and
                  Andreas Holzinger and
                  Joaquim Filipe},
  title        = {On the Feasibility of Side-Channel Attacks in a Virtualized Environment},
  booktitle    = {E-Business and Telecommunications - 11th International Joint Conference,
                  {ICETE} 2014, Vienna, Austria, August 28-30, 2014, Revised Selected
                  Papers},
  series       = {Communications in Computer and Information Science},
  volume       = {554},
  pages        = {319--339},
  publisher    = {Springer},
  year         = {2014},
  url          = {https://doi.org/10.1007/978-3-319-25915-4\_17},
  doi          = {10.1007/978-3-319-25915-4\_17},
  timestamp    = {Tue, 16 Aug 2022 23:04:29 +0200},
  biburl       = {https://dblp.org/rec/conf/icete/Vateva-GurovaLP14.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/ndss/PellegrinoB14,
  author       = {Giancarlo Pellegrino and
                  Davide Balzarotti},
  title        = {Toward Black-Box Detection of Logic Flaws in Web Applications},
  booktitle    = {21st Annual Network and Distributed System Security Symposium, {NDSS}
                  2014, San Diego, California, USA, February 23-26, 2014},
  publisher    = {The Internet Society},
  year         = {2014},
  url          = {https://www.ndss-symposium.org/ndss2014/toward-black-box-detection-logic-flaws-web-applications},
  timestamp    = {Mon, 01 Feb 2021 08:42:18 +0100},
  biburl       = {https://dblp.org/rec/conf/ndss/PellegrinoB14.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/secrypt/Vateva-GurovaLPS14,
  author       = {Tsvetoslava Vateva{-}Gurova and
                  Jesus Luna and
                  Giancarlo Pellegrino and
                  Neeraj Suri},
  editor       = {Mohammad S. Obaidat and
                  Andreas Holzinger and
                  Pierangela Samarati},
  title        = {Towards a Framework for Assessing the Feasibility of Side-channel
                  Attacks in Virtualized Environments},
  booktitle    = {{SECRYPT} 2014 - Proceedings of the 11th International Conference
                  on Security and Cryptography, Vienna, Austria, 28-30 August, 2014},
  pages        = {113--124},
  publisher    = {SciTePress},
  year         = {2014},
  url          = {https://doi.org/10.5220/0005052101130124},
  doi          = {10.5220/0005052101130124},
  timestamp    = {Wed, 11 Aug 2021 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/conf/secrypt/Vateva-GurovaLPS14.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@phdthesis{DBLP:phd/hal/Pellegrino13,
  author       = {Giancarlo Pellegrino},
  title        = {Detection of logic flaws in multi-party business applications via
                  security testing. (D{\'{e}}tection d'anomalies logiques dans
                  les logiciels d'entreprise multi-partis {\`{a}} travers des tests
                  de s{\'{e}}curit{\'{e}})},
  school       = {T{\'{e}}l{\'{e}}com ParisTech, France},
  year         = {2013},
  url          = {https://tel.archives-ouvertes.fr/tel-01194884},
  timestamp    = {Tue, 21 Jul 2020 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/phd/hal/Pellegrino13.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@article{DBLP:journals/compsec/ArmandoCCCPS13,
  author       = {Alessandro Armando and
                  Roberto Carbone and
                  Luca Compagna and
                  Jorge Cu{\'{e}}llar and
                  Giancarlo Pellegrino and
                  Alessandro Sorniotti},
  title        = {An authentication flaw in browser-based Single Sign-On protocols:
                  Impact and remediations},
  journal      = {Comput. Secur.},
  volume       = {33},
  pages        = {41--58},
  year         = {2013},
  url          = {https://doi.org/10.1016/j.cose.2012.08.007},
  doi          = {10.1016/J.COSE.2012.08.007},
  timestamp    = {Mon, 28 Aug 2023 01:00:00 +0200},
  biburl       = {https://dblp.org/rec/journals/compsec/ArmandoCCCPS13.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/pts/PellegrinoCM13,
  author       = {Giancarlo Pellegrino and
                  Luca Compagna and
                  Thomas Morreggia},
  editor       = {H{\"{u}}sn{\"{u}} Yenig{\"{u}}n and
                  Cemal Yilmaz and
                  Andreas Ulrich},
  title        = {A Tool for Supporting Developers in Analyzing the Security of Web-Based
                  Security Protocols},
  booktitle    = {Testing Software and Systems - 25th {IFIP} {WG} 6.1 International
                  Conference, {ICTSS} 2013, Istanbul, Turkey, November 13-15, 2013,
                  Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {8254},
  pages        = {277--282},
  publisher    = {Springer},
  year         = {2013},
  url          = {https://doi.org/10.1007/978-3-642-41707-8\_19},
  doi          = {10.1007/978-3-642-41707-8\_19},
  timestamp    = {Tue, 14 May 2019 10:00:53 +0200},
  biburl       = {https://dblp.org/rec/conf/pts/PellegrinoCM13.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/tacas/ArmandoAABCCCCCCEFMMOPPRRDTV12,
  author       = {Alessandro Armando and
                  Wihem Arsac and
                  Tigran Avanesov and
                  Michele Barletta and
                  Alberto Calvi and
                  Alessandro Cappai and
                  Roberto Carbone and
                  Yannick Chevalier and
                  Luca Compagna and
                  Jorge Cu{\'{e}}llar and
                  Gabriel Erzse and
                  Simone Frau and
                  Marius Minea and
                  Sebastian M{\"{o}}dersheim and
                  David von Oheimb and
                  Giancarlo Pellegrino and
                  Serena Elisa Ponta and
                  Marco Rocchetto and
                  Micha{\"{e}}l Rusinowitch and
                  Mohammad Torabi Dashti and
                  Mathieu Turuani and
                  Luca Vigan{\`{o}}},
  editor       = {Cormac Flanagan and
                  Barbara K{\"{o}}nig},
  title        = {The {AVANTSSAR} Platform for the Automated Validation of Trust and
                  Security of Service-Oriented Architectures},
  booktitle    = {Tools and Algorithms for the Construction and Analysis of Systems
                  - 18th International Conference, {TACAS} 2012, Held as Part of the
                  European Joint Conferences on Theory and Practice of Software, {ETAPS}
                  2012, Tallinn, Estonia, March 24 - April 1, 2012. Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {7214},
  pages        = {267--282},
  publisher    = {Springer},
  year         = {2012},
  url          = {https://doi.org/10.1007/978-3-642-28756-5\_19},
  doi          = {10.1007/978-3-642-28756-5\_19},
  timestamp    = {Fri, 27 Dec 2019 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/tacas/ArmandoAABCCCCCCEFMMOPPRRDTV12.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/tap/ArmandoPCMB12,
  author       = {Alessandro Armando and
                  Giancarlo Pellegrino and
                  Roberto Carbone and
                  Alessio Merlo and
                  Davide Balzarotti},
  editor       = {Achim D. Brucker and
                  Jacques Julliand},
  title        = {From Model-Checking to Automated Testing of Security Protocols: Bridging
                  the Gap},
  booktitle    = {Tests and Proofs - 6th International Conference, TAP@TOOLS 2012, Prague,
                  Czech Republic, May 31 - June 1, 2012. Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {7305},
  pages        = {3--18},
  publisher    = {Springer},
  year         = {2012},
  url          = {https://doi.org/10.1007/978-3-642-30473-6\_3},
  doi          = {10.1007/978-3-642-30473-6\_3},
  timestamp    = {Tue, 23 Jun 2020 17:37:39 +0200},
  biburl       = {https://dblp.org/rec/conf/tap/ArmandoPCMB12.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/essos/ArsacCPP11,
  author       = {Wihem Arsac and
                  Luca Compagna and
                  Giancarlo Pellegrino and
                  Serena Elisa Ponta},
  editor       = {{\'{U}}lfar Erlingsson and
                  Roel J. Wieringa and
                  Nicola Zannone},
  title        = {Security Validation of Business Processes via Model-Checking},
  booktitle    = {Engineering Secure Software and Systems - Third International Symposium,
                  ESSoS 2011, Madrid, Spain, February 9-10, 2011. Proceedings},
  series       = {Lecture Notes in Computer Science},
  volume       = {6542},
  pages        = {29--42},
  publisher    = {Springer},
  year         = {2011},
  url          = {https://doi.org/10.1007/978-3-642-19125-1\_3},
  doi          = {10.1007/978-3-642-19125-1\_3},
  timestamp    = {Tue, 14 May 2019 10:00:49 +0200},
  biburl       = {https://dblp.org/rec/conf/essos/ArsacCPP11.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/sec/ArmandoCCCPS11,
  author       = {Alessandro Armando and
                  Roberto Carbone and
                  Luca Compagna and
                  Jorge Cu{\'{e}}llar and
                  Giancarlo Pellegrino and
                  Alessandro Sorniotti},
  editor       = {Jan Camenisch and
                  Simone Fischer{-}H{\"{u}}bner and
                  Yuko Murayama and
                  Armand Portmann and
                  Carlos Rieder},
  title        = {From Multiple Credentials to Browser-Based Single Sign-On: Are We
                  More Secure?},
  booktitle    = {Future Challenges in Security and Privacy for Academia and Industry
                  - 26th {IFIP} {TC} 11 International Information Security Conference,
                  {SEC} 2011, Lucerne, Switzerland, June 7-9, 2011. Proceedings},
  series       = {{IFIP} Advances in Information and Communication Technology},
  volume       = {354},
  pages        = {68--79},
  publisher    = {Springer},
  year         = {2011},
  url          = {https://doi.org/10.1007/978-3-642-21424-0\_6},
  doi          = {10.1007/978-3-642-21424-0\_6},
  timestamp    = {Fri, 27 Dec 2019 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/sec/ArmandoCCCPS11.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
@inproceedings{DBLP:conf/icst/ArmandoCCLP10,
  author       = {Alessandro Armando and
                  Roberto Carbone and
                  Luca Compagna and
                  Keqin Li and
                  Giancarlo Pellegrino},
  title        = {Model-Checking Driven Security Testing of Web-Based Applications},
  booktitle    = {Third International Conference on Software Testing, Verification and
                  Validation, {ICST} 2010, Paris, France, April 7-9, 2010, Workshops
                  Proceedings},
  pages        = {361--370},
  publisher    = {{IEEE} Computer Society},
  year         = {2010},
  url          = {https://doi.org/10.1109/ICSTW.2010.54},
  doi          = {10.1109/ICSTW.2010.54},
  timestamp    = {Thu, 23 Mar 2023 00:00:00 +0100},
  biburl       = {https://dblp.org/rec/conf/icst/ArmandoCCLP10.bib},
  bibsource    = {dblp computer science bibliography, https://dblp.org}
}
a service of  Schloss Dagstuhl - Leibniz Center for Informatics